TROYANOSYVIRUS
Voltar para CVEs

CVE-2025-9081

LOW
3.1

Descricao

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration

Detalhes CVE

Pontuacao CVSS v3.13.1
SeveridadeLOW
Vetor CVSSCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Vetor de ataqueNETWORK
ComplexidadeHIGH
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado9/19/2025
Ultima modificacao9/25/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

mattermost:mattermost_server

Fraquezas (CWE)

CWE-639

Referencias

https://mattermost.com/security-updates(responsibledisclosure@mattermost.com)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.