Логотип exploitDog
bind:CVE-2025-36530
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-36530

Количество 3

Количество 3

nvd логотип

CVE-2025-36530

6 месяцев назад

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2025-36530

6 месяцев назад

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5 ...

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-gq3r-5833-5532

6 месяцев назад

Mattermost Fails to Validate File Paths

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-36530

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.

CVSS3: 6.8
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-36530

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5 ...

CVSS3: 6.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-gq3r-5833-5532

Mattermost Fails to Validate File Paths

CVSS3: 6.8
0%
Низкий
6 месяцев назад

Уязвимостей на страницу