Vulnerability CVE-2023-1774


Published: 2023-03-31

Description:
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.

 References:
https://mattermost.com/security-updates/

Copyright 2026, cxsecurity.com

 

Back to Top