Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.4, <= 10.4.2
- >= 10.3, <= 10.3.3
- >= 9.11, <= 9.11.8
- >= 10.5, <= 10.5.0
A vulnerability exists in Mattermost versions 10.4.x through 10.4.2, 10.3.x through 10.3.3, and 9.11.x through 9.11.8, allowing authenticated users to create or update bookmarks in archived channels. The issue arises because these versions do not properly restrict bookmark actions in channels that have been archived.
Exploitation of this vulnerability could lead to unauthorized bookmark creation or modification in archived channels, potentially allowing users to manipulate channel references or highlight important messages inappropriately.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.