Vulnerabilities > Mattermost > Mattermost Server > 9.5.2

DATE CVE VULNERABILITY TITLE RISK
2024-04-26 CVE-2024-4198 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.
network
low complexity
mattermost
2.7