Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 9.11.0, <= 9.11.5
A vulnerability exists in Mattermost versions 9.11.x prior to 9.11.5, allowing team admins without invitation permissions to invite users. This is achieved by changing the 'allow_open_invite' field after making their team public, thereby bypassing permission restrictions.
Exploitation of this vulnerability could lead to unauthorized user invitations, allowing invited users to join teams where they would not typically be permitted.
Users can upgrade to Mattermost version 10.9.010.5.69.11.1610.8.110.7.310.6.6 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.