Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.5.0, <= 10.5.5
- >= 9.11.0, <= 9.11.15
- >= 10.8.0, <= 10.8.0
- >= 10.7.0, <= 10.7.2
- >= 10.6.0, <= 10.6.5
A vulnerability exists in Mattermost versions 10.5.x through 10.5.5, 9.11.x through 9.11.15, 10.8.x through 10.8.0, 10.7.x through 10.7.2, and 10.6.x through 10.6.5. The issue arises because these versions do not properly sanitize filenames in the archive extractor. This flaw enables authenticated users to upload archives containing path traversal sequences in filenames, allowing them to write files to arbitrary locations on the filesystem. This could potentially lead to remote code execution. The vulnerability is present in instances where file uploads and document content extraction are enabled, settings that are typically activated by default.
Exploitation of this vulnerability could result in unauthorized file writes to the filesystem, with the potential for remote code execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.