CVE-2025-0503
MEDIUM EPSS 14.2%
Published Feb 14, 20251y ago · Modified Jun 17, 20262w ago
5.3 CVSS 3.1
Published Feb 14, 2025 1y ago
Last Modified Jun 17, 2026 2w ago
Description
Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity None
Availability None
Threat Intelligence
EPSS Exploit Probability
14.2% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-754
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| mattermost | mattermost_server | * | ≥9.11.0 – <9.11.7 |
References 1
- mattermost.com https://mattermost.com/security-updates
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.