Files
CVEs-PoC/2025/CVE-2025-2570.md
T
2025-09-29 21:09:30 +02:00

946 B

CVE-2025-2570

Description

Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check RestrictSystemAdmin setting if user doesn't have access to ExperimentalSettings which allows a System Manager to access ExperimentSettings when RestrictSystemAdmin is true via System Console.

POC

Reference

Github

No PoCs found on GitHub currently.