Total vulnerabilities in the database
Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.
CVSS v3:
CWEs:
OWASP TOP 10: