cve/2024/CVE-2024-1952.md
2025-09-29 21:09:30 +02:00

915 B

CVE-2024-1952

Description

Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of.

POC

Reference

Github

No PoCs found on GitHub currently.