Vulnerability Details CVE-2023-5193
Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 38.8%
CVSS Severity
CVSS v3 Score 4.9
Products affected by CVE-2023-5193
-
cpe:2.3:a:mattermost:mattermost:*