// For flags

CVE-2023-47865

Username and Icon override can be used by members when Hardened Mode is enabled

Severity Score

4.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled

Mattermost no verifica si el modo reforzado está habilitado al anular el nombre de usuario y/o el ícono al publicar una publicación. Si la configuración permitía que las integraciones anularan el nombre de usuario y la imagen de perfil al publicar, un miembro también podría anular el nombre de usuario y el ícono al realizar una publicación, incluso si la configuración del Hardened Mode estaba habilitada.

*Credits: Eva Sarafianou
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-11-22 CVE Reserved
  • 2023-11-27 CVE Published
  • 2024-08-02 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-284: Improper Access Control
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
URL Date SRC
https://mattermost.com/security-updates 2023-12-01
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mattermost
Search vendor "Mattermost"
Mattermost
Search vendor "Mattermost" for product "Mattermost"
<= 7.8.12
Search vendor "Mattermost" for product "Mattermost" and version " <= 7.8.12"
-
Affected
Mattermost
Search vendor "Mattermost"
Mattermost
Search vendor "Mattermost" for product "Mattermost"
>= 8.0.0 <= 8.1.3
Search vendor "Mattermost" for product "Mattermost" and version " >= 8.0.0 <= 8.1.3"
-
Affected