7.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Description
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.
Basic Information
ID
CVE-2025-54478
Source
Mattermost
Published
Aug 11, 2025 at 18:57
Modified
Aug 11, 2025 at 19:40
Affected Product
Vendor
Mattermost
Product
Mattermost Confluence Plugin
Affected Versions
Mattermost Mattermost Confluence Plugin 0