TROYANOSYVIRUS
Volver a CVEs

CVE-2025-13821

MEDIUM
5.7

Descripcion

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email verification events. Mattermost Advisory ID: MMSA-2025-00560

Detalles CVE

Puntuacion CVSS v3.15.7
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioREQUIRED
Publicado2/16/2026
Ultima modificacion2/18/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

mattermost:mattermost_server

Debilidades (CWE)

CWE-200

Referencias

https://mattermost.com/security-updates(responsibledisclosure@mattermost.com)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.