Show filters
412 Total Results
Displaying 41-50 of 412
Sort by:
Attacker Value
Unknown

CVE-2024-45833

Disclosure Date: September 16, 2024 (last updated February 26, 2025)
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..
Attacker Value
Unknown

CVE-2024-39613

Disclosure Date: September 16, 2024 (last updated February 26, 2025)
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.
Attacker Value
Unknown

CVE-2024-43105

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.
0
Attacker Value
Unknown

CVE-2024-43780

Disclosure Date: August 22, 2024 (last updated February 26, 2025)
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
Attacker Value
Unknown

CVE-2024-42497

Disclosure Date: August 22, 2024 (last updated February 26, 2025)
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write operations on teams.
Attacker Value
Unknown

CVE-2024-40884

Disclosure Date: August 22, 2024 (last updated February 26, 2025)
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
Attacker Value
Unknown

CVE-2024-8071

Disclosure Date: August 22, 2024 (last updated February 26, 2025)
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to include the `manage_system` permission, effectively becoming a System Admin.
Attacker Value
Unknown

CVE-2024-43813

Disclosure Date: August 22, 2024 (last updated February 26, 2025)
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.
Attacker Value
Unknown

CVE-2024-42411

Disclosure Date: August 22, 2024 (last updated February 26, 2025)
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.
Attacker Value
Unknown

CVE-2024-40886

Disclosure Date: August 22, 2024 (last updated February 26, 2025)
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in User Management page of the system console.