CVE-2025-22449

Publication date

2025-01-09 06:54:53

Family

Mattermost

State

PUBLISHED

Description

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.