CVE-2025-13870
BaseFortify
Publication date: 2025-12-02
Last updated on: 2025-12-03
Assigner: Mattermost, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mattermost | mattermost_server | From 10.5.0 (inc) to 10.5.13 (exc) |
| mattermost | mattermost_server | From 10.11.0 (inc) to 10.11.5 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Mattermost versions 10.11.x <= 10.11.4 and 10.5.x <= 10.5.12 occurs because the software fails to properly validate user permissions when accessing files and subscribing to blocks in Boards. As a result, an authenticated user can access files and subscribe to blocks from other boards that they do not have permission to access.
How can this vulnerability impact me? :
The impact of this vulnerability is that an authenticated user could gain unauthorized access to files and board blocks they should not have access to, potentially leading to information disclosure or unauthorized data access within the Mattermost Boards feature.