← Back

CVE-2025-9072

nvd nist
Published: Sep 15, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an attacker-controlled URL.

Affected (3)

1 product
Mattermost Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Mattermost
From 10.10.0 to 10.10.2
From 10.5.0 to 10.5.10
From 10.9.0 to 10.9.5

References (1)

Source: responsibledisclosure@mattermost.com
Vendor Advisory

Timeline

No history available yet.