Vulnerability CVE-2023-27265


Published: 2023-02-27

Description:
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

 References:
https://mattermost.com/security-updates/

Copyright 2026, cxsecurity.com

 

Back to Top