CVE-2025-2570
15.05.2025, 16:15
Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true via System Console.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Vulnerability Media Exposure
References