CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. See the original NVD description below for full technical details.
CVE
CVE-2019-20887
Severity
MEDIUM
CVSS
4.3
EPSS
0.65%
Original NVD Description
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.
Related CVEs
Other vulnerabilities affecting the same vendor(s)