Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 9.11.0, <= 9.11.8
A vulnerability exists in Mattermost versions 9.11.x prior to 9.11.8, where the application fails to require explicit approval before assigning a team admin to a private channel. This oversight allows team admins to join private channels through specially crafted permalink links without the consent of the channel admins.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a team admin to access private channels without proper approval.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.