CVE-2023-4107
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2023-4107: A vulnerability was discovered in Mattermost, an open-source team communication platform. The flaw allows user managers to bypass permission checks and update system admin details, including email, first name, and last name, without proper authorization. This issue poses a significant risk as system admin accounts often have extensive permissions, enabling potential attackers to gain unauthorized access or manipulate important system settings. Organizations using Mattermost are advised to apply the appropriate patch or upgrade to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.