- Description
- Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.
- Source
- responsibledisclosure@mattermost.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 3.1
- Impact score
- 1.4
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity
- LOW
- responsibledisclosure@mattermost.com
- CWE-384
- Hype score
- Not currently trending
CVE-2025-1412 Privilege Escalation in Mattermost via Incomplete Session Invalidation https://t.co/30YqNHx97k
@VulmonFeeds
24 Feb 2025
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-1412 Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalat… https://t.co/pToC3jjW0g
@CVEnew
24 Feb 2025
483 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes