Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.5, <= 10.5.7
- >= 9.11, <= 9.11.16
A vulnerability exists in Mattermost versions 10.5.x through 10.5.7 and 9.11.x through 9.11.16, where the application fails to properly negotiate a new token when a user accepts an invite. This flaw allows an individual who intercepts both the invite and password to send synchronization payloads to the original server via the REST API.
Exploitation of this vulnerability could lead to unauthorized synchronization payloads being sent to the server, potentially causing unintended actions or data modifications.
Users can upgrade to Mattermost versions 10.9.0 or 10.8.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.