2024-05-26 14:27:05 +02:00
### [CVE-2019-20887](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20887)



### Description
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.
### POC
#### Reference
- https://mattermost.com/security-updates/
2024-06-09 00:33:16 +00:00
- https://mattermost.com/security-updates/
2024-05-26 14:27:05 +02:00
#### Github
No PoCs found on GitHub currently.