Files
CVEs-PoC/2025/CVE-2025-6465.md
T
2025-09-29 21:09:30 +02:00

1.1 KiB

CVE-2025-6465

Description

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.

POC

Reference

Github

No PoCs found on GitHub currently.