Sensitive Information Exposure in Mattermost Server by Mattermost
CVE-2016-11075
5.3MEDIUM
Summary
An issue was discovered in earlier versions of Mattermost Server that can lead to unauthorized access to sensitive data. Attackers may exploit this vulnerability to retrieve team URLs through the API, posing a significant risk to the confidentiality of the affected systems. Proper security measures and upgrades to the latest version are essential to mitigate this risk effectively.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved