CVE-2025-20033
Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to users with the sysconsole_read_plugins permission via creating a post with the custom_pl_notification type and specific props.
Vendor
Product
CWE
Yayın Tarihi
2025-01-09 07:15:28
Güncelleme
2025-10-02 17:26:14
Source Identifier
responsibledisclosure@mattermost.com
KEV Date Added
-