Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 11.7, <= 11.7.2
- >= 11.6, <= 11.6.4
- >= 10.11, <= 10.11.19
A vulnerability exists in Mattermost versions 11.7.x through 11.7.2, 11.6.x through 11.6.4, and 10.11.x through 10.11.19. The issue arises because the application fails to properly verify that the channel referenced in an action cookie corresponds to the channel of the target post. This flaw enables an authenticated user without access to a private channel to invoke interactive post actions on posts within that channel, using a cookie obtained from any accessible channel.
Exploitation of this vulnerability allows for unauthorized interaction with posts in private channels, potentially leading to unintended modifications or actions on those posts.
Users can upgrade to Mattermost version 11.8.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.