Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost存在安全漏洞,该漏洞源于存在权限验证错误问题,导致攻击者可通过get/api/v4/teams/<team id>/channels/deleted端点获取另一个团队的详细信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 0 ~ 9.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-48732 | 4.3 MEDIUM | Keywords that trigger mentions are leaked to other users |
| CVE-2023-50333 | 3.7 LOW | Lack of restriction to manage group names for freshly demoted guests |
No comments yet