CVE-2025-11794
BaseFortify
Publication date: 2025-11-14
Last updated on: 2025-11-19
Assigner: Mattermost, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mattermost | mattermost_server | From 10.5.0 (inc) to 10.5.12 (exc) |
| mattermost | mattermost_server | From 10.11.0 (inc) to 10.11.4 (exc) |
| mattermost | mattermost_server | From 10.12.0 (inc) to 10.12.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in certain Mattermost versions where user data is not properly sanitized. This flaw allows system administrators to access sensitive information such as password hashes and multi-factor authentication (MFA) secrets through a specific API endpoint.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to sensitive authentication data by system administrators, potentially compromising user accounts by exposing password hashes and MFA secrets. This could result in account takeover or other security breaches.