Total vulnerabilities in the database
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
Software | From | Fixed in |
---|---|---|
mattermost / mattermost_server | 7.7.1 | 7.7.1.x |
mattermost / mattermost_server | - | 7.1.6 |
![]() |
3.3.0 | 7.1.6 |
![]() |
7.7.0 | 7.7.2 |
![]() |
7.1.0 | 7.1.6 |
![]() |
5.0.0 | 7.1.6 |
![]() |
6.0.0 | 7.1.6 |