CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 2.7. See the original NVD description below for full technical details.
CVE
CVE-2024-4195
Severity
LOW
CVSS
2.7
EPSS
0.50%
Original NVD Description
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.
Related CVEs
Other vulnerabilities affecting the same vendor(s)