Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.5.0, <= 10.5.10
- >= 10.11.0, <= 10.11.2
A vulnerability exists in Mattermost versions 10.5.x through 10.5.10 and 10.11.x through 10.11.2, where guest user permissions are not properly validated when adding members to private channels. This flaw allows guest users to add any team members to their private channels via the channels/{channel_id}/members API endpoint.
Exploitation of this vulnerability could lead to unauthorized addition of team members to private channels by guest users.
Users can upgrade to Mattermost version 11.0.0 or 10.12.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.