ZeroHour

CVE-2022-1385

PoC
CVSS 3.1
4.6 medium
EPSS
<1%p56
Published
()
Modified
Description

Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.

Vendors
mattermost
Products
mattermost server
Weakness
CWE-664, CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.