cve/2023/CVE-2023-6547.md
2024-05-25 21:48:12 +02:00

846 B

CVE-2023-6547

Description

Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team. 

POC

Reference

No PoCs from references.

Github