CVE-2025-22449

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.
References
Configurations

No configuration.

History

09 Jan 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-09 07:15

Updated : 2025-01-09 07:15


NVD link : CVE-2025-22449

Mitre link : CVE-2025-22449

CVE.ORG link : CVE-2025-22449


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization