Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.5.0, <= 10.5.1
- >= 10.4.0, <= 10.4.3
- >= 9.11.0, <= 9.11.9
A vulnerability exists in Mattermost versions 10.5.x through 10.5.1, 10.4.x through 10.4.3, and 9.11.x through 9.11.9, where the application fails to properly invalidate the cache when a user account is converted to a bot. This flaw enables an attacker to log in to the bot account once using normal credentials.
Exploitation of this vulnerability allows for unauthorized access to a bot account, enabling a one-time login using the account's regular credentials.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.