cbcvebase.
CVE-2023-50333
published 2024-01-02

CVE-2023-50333: Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group…

PriorityP418medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.32%
24.4th percentile
Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.

Affected

3 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost_server_v8>= 0 < 8.1.78.1.7
mattermostmattermost<= 9.2.2
mattermostmattermost_server< 8.1.78.1.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.