Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin
CVE ID: CVE-2023-2515
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.7
Vendor: Mattermost
Product: Mattermost
EPSS Score: 0.11% (probability of being exploited)
EPSS Percentile: 45.29% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)