CVE-2025-1472 MEDIUM

CVE-2025-1472: Unauthorized View Access to Site Statistics and Team Statistics

Vendor Mattermost
Product Mattermost
Weakness CWE-863 · Incorrect authorization
Published March 19, 2025
Last update March 19, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.

Key dates

02Disclosure timeline

March 19, 2025 CVE published
March 19, 2025 Record updated