CVE-2025-32093

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to perform unauthorized modifications to system administrators via improper permission validation.
References
Configurations

No configuration.

History

15 Apr 2025, 18:39

Type Values Removed Values Added
Summary
  • (es) Las versiones de Mattermost 10.5.x &lt;= 10.5.1, 10.4.x &lt;= 10.4.3, 9.11.x &lt;= 9.11.9 no restringen ciertas operaciones de los administradores del sistema solo a otros administradores del sistema, lo que permite que los usuarios de administración granular delegados con el permiso "Editar otros usuarios" realicen modificaciones no autorizadas en los administradores del sistema a través de una validación de permisos incorrecta.

14 Apr 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-14 07:15

Updated : 2025-04-15 18:39


NVD link : CVE-2025-32093

Mitre link : CVE-2025-32093

CVE.ORG link : CVE-2025-32093


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization