Exploit maturity not defined.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/mattermost/mattermost/server/channels/store/sqlstore
to version 9.11.7, 10.4.0 or higher.
Affected versions of this package are vulnerable to Improper Check for Unusual or Exceptional Conditions due to the improper filtering of the deleted_channels
endpoint. An attacker can infer user IDs and other metadata from deleted DMs by exploiting the endpoint if someone had manually marked DMs as deleted in the database.