Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 9.11.0, <= 9.11.6
- >= 10.4.0, <= 10.4.1
A vulnerability exists in Mattermost versions 9.11.x prior to 9.11.6 and 10.4.x prior to 10.4.1, allowing users to escalate privileges by converting them to bots without invalidating active sessions. This oversight enables the newly converted bot to inherit permissions that could be misused, depending on the bot's granted rights.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing users to gain elevated rights and access within the Mattermost application.
Users are advised to upgrade to Mattermost versions 9.11.6 or 10.4.1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.