ZeroHour

CVE-2023-27265

CVSS 3.1
2.7 low
EPSS
<1%p43
Published
()
Modified
Description

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

Vendors
mattermost
Products
mattermost server
Weakness
CWE-200, CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.