Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 11.5, <= 11.5.1
- >= 11.4, <= 11.4.3
A vulnerability exists in Mattermost versions 11.5.x through 11.5.1 and 11.4.x through 11.4.3, where the application fails to properly validate the X-Requested-With header on the burn-on-read reveal endpoint. This flaw allows an authenticated channel member to reveal a burn-on-read message without the recipient's consent by using a manipulated Markdown image tag.
Exploitation of this vulnerability allows for unauthorized revelation of burn-on-read messages, bypassing recipient consent.
Users can upgrade to Mattermost versions 11.7.0 or 11.7.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.