CVE-2023-6202
27.11.2023, 10:15
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another userto get their information (e.g. name, surname, nickname) via Mattermost Boards.Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost | 𝑥 ≤ 7.8.12 |
mattermost | mattermost | 8.0.0 ≤ 𝑥 ≤ 8.1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration