Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 9.11.0, <= 9.11.8
An authorization vulnerability has been identified in Mattermost versions 9.11.x prior to 9.11.8. The issue arises in the Viewer role, which is not properly authorized, allowing attackers with this role—especially those configured with No Access to Reporting—to still view team and site statistics.
Exploitation of this vulnerability allows unauthorized access to team and site statistics, bypassing the intended restrictions of the Viewer role.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.