Site icon API Security Blog

Improper Authorization

github.com/mattermost/mattermost is vulnerable to Improper Authorization. The vulnerability is caused due to improper permission validation while a user views archived public channels. One member of a team can view a channel of another team member via GET call to the /api/v4/teams//channels/deleted…Read More

Exit mobile version