5.3

CVSS4.0

CVE-2024-5366 - SourceCodester Best House Rental Management System edit-cate.php sql injection

A vulnerability has been found in SourceCodester Best House Rental Management System up to 1.0 and classified as critical. This vulnerability affects unknown code of the file edit-cate.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit…

📅 Published: May 26, 2024, 2 p.m. 🔄 Last Modified: Feb. 10, 2025, 2:42 p.m.

4.3

CVSS3.1

CVE-2024-29215 - Slash commands run in channel without channel membership via playbook task commands

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel they are not a member of via linking a playbook run to that channel and running a slash command as a playbook task comman…

📅 Published: May 26, 2024, 1:33 p.m. 🔄 Last Modified: July 8, 2025, 6:02 p.m.

5.7

CVSS3.1

CVE-2024-36255 - Post actions can run playbook checklist task commands

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash command in…

📅 Published: May 26, 2024, 1:32 p.m. 🔄 Last Modified: Sept. 30, 2025, 3:29 p.m.

3.1

CVSS3.1

CVE-2024-36241 - /playbook add slash command allows viewing arbitrary post contents

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command

📅 Published: May 26, 2024, 1:32 p.m. 🔄 Last Modified: Sept. 30, 2025, 3:28 p.m.

4.3

CVSS3.1

CVE-2024-31859 - Member promoted to channel admin via playbooks run linking to channel

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel admin

📅 Published: May 26, 2024, 1:31 p.m. 🔄 Last Modified: Sept. 30, 2025, 3:20 p.m.

4.3

CVSS3.1

CVE-2024-5270 - SAML to email switch possible when email signin is disabled

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to switch from SAML to Email. This allows the user to switch their authentication mail from SAML to email and possibly edit p…

📅 Published: May 26, 2024, 1:30 p.m. 🔄 Last Modified: Sept. 30, 2025, 3:47 p.m.

4.3

CVSS3.1

CVE-2024-5272 - Run Details leak to guest via webhook event "custom_playbooks_playbook_run_updated"

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished.

📅 Published: May 26, 2024, 1:29 p.m. 🔄 Last Modified: Sept. 30, 2025, 3:48 p.m.

5.9

CVSS3.1

CVE-2024-32045 - Playbook run link to private channel grants channel access

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were not members of.

📅 Published: May 26, 2024, 1:29 p.m. 🔄 Last Modified: Sept. 30, 2025, 3:24 p.m.

4.3

CVSS3.1

CVE-2024-34152 - Playbook Run Metadata leak to Guest

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the metadata of a public playbook run that linked to the channel they are guest via sending an RHSRuns GraphQL query request to the server

📅 Published: May 26, 2024, 1:28 p.m. 🔄 Last Modified: Sept. 30, 2025, 3:27 p.m.

4.3

CVSS3.1

CVE-2024-34029 - AD/LDAP Group Members Leak

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a cha…

📅 Published: May 26, 2024, 1:27 p.m. 🔄 Last Modified: Sept. 30, 2025, 3:26 p.m.
Total resulsts: 349182
Page 9668 of 34,919
« previous page » next page
Filters