cve/2023/CVE-2023-27265.md
2024-06-18 02:51:15 +02:00

798 B

CVE-2023-27265

Description

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

POC

Reference

Github

No PoCs found on GitHub currently.