Privilege escalation to system admin via personal access tokens
CVE-2023-2515
8.8HIGH
Summary
Mattermost contains a vulnerability that allows users with specific permissions to edit other users and create personal access tokens, potentially enabling them to elevate their privileges to that of a system administrator. This flaw underscores the importance of ensuring proper access controls and user permissions within the Mattermost platform to protect sensitive system functionalities.
Affected Version(s)
Mattermost 0 <= 7.1.7
Mattermost 0 <= 7.7.3
Mattermost 0 <= 7.8.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Eva Sarafianou