CVE 6.8 MEDIUM

Arbitrary file read by system admin via path traversal_CVE-2025-6233

6.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Description

Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.

Basic Information

ID CVE-2025-6233
Source Mattermost
Published Jul 18, 2025 at 09:09
Modified Jul 18, 2025 at 12:30

Affected Product

Vendor Mattermost
Product Mattermost
Version 10.8.0
Affected Versions Mattermost Mattermost 10.8.0
Mattermost Mattermost 10.7.0
Mattermost Mattermost 10.5.0
Mattermost Mattermost 9.11.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.