NA

CVE-2023-27266

Published: 27/02/2023 Updated: 07/11/2023
CVSS v3 Base Score: 2.7 | Impact Score: 1.4 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mattermost mattermost server