An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-21253.json"