← Back

CVE-2025-1472

nvd nist
Published: Mar 19, 2025Modified: Oct 1, 2025

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: responsibledisclosure@mattermost.com (Secondary)

Description

Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.

Affected (1)

1 product
Mattermost Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 9.11.0 to 9.11.9

References (1)

Source: responsibledisclosure@mattermost.com
Vendor Advisory

Timeline

No history available yet.