ZeroHour

CVE-2024-4198

CVSS 3.1
2.7 low
EPSS
<1%p41
Published
()
Modified
Description

Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.

Vendors
mattermost
Products
mattermost server
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.