Loading HuntDB...

GHSA-m3fh-qqv6-hgxx

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

Related CVEs

Key Information

GHSA ID
GHSA-m3fh-qqv6-hgxx
Published
August 22, 2024 9:30 AM
Last Modified
August 23, 2024 6:33 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.