Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 11.5.0, <= 11.5.1
- >= 10.11.0, <= 10.11.13
A vulnerability exists in Mattermost versions 11.5.x through 11.5.1 and 10.11.x through 10.11.13, allowing authenticated users to bypass the PostEditTimeLimit restriction on non-message post fields. This flaw enables users to alter post file attachments, properties, and pin status after the designated edit period has lapsed, using the post patch and update API endpoints.
Exploitation of this vulnerability could lead to unauthorized modifications of post attachments, properties, and pin statuses, potentially disrupting communication and information sharing within Mattermost channels.
Users can upgrade to Mattermost versions 11.7.0 or 11.7.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.