Privilege escalation to system admin via personal access tokens
CVE-2023-2515
8.8HIGH
What is CVE-2023-2515?
Mattermost contains a vulnerability that allows users with specific permissions to edit other users and create personal access tokens, potentially enabling them to elevate their privileges to that of a system administrator. This flaw underscores the importance of ensuring proper access controls and user permissions within the Mattermost platform to protect sensitive system functionalities.
Affected Version(s)
Mattermost 0 <= 7.1.7
Mattermost 0 <= 7.7.3
Mattermost 0 <= 7.8.2