Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.5.0, <= 10.5.1
- >= 9.11.0, <= 9.11.9
A vulnerability exists in Mattermost versions 10.5.x prior to 10.5.1 and 9.11.x prior to 9.11.9, where the application fails to verify if a file has been deleted when a bookmark is created. This oversight allows an attacker who knows the IDs of deleted files to retrieve metadata about those files through the bookmark creation process.
Exploitation of this vulnerability could lead to unauthorized access to metadata of deleted files, potentially including sensitive information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.