SQL Injection Vulnerability in Mattermost Project Management Software
CVE-2025-24490

9.6CRITICAL

Key Information:

Vendor
Mattermost
Vendor
CVE Published:
24 February 2025

Summary

Certain versions of Mattermost are vulnerable to SQL injection due to the improper use of prepared statements in the SQL query responsible for reordering boards. This flaw allows attackers to craft specific requests that can potentially retrieve sensitive data from the database, compromising the confidentiality and integrity of the information stored. It is crucial for users of affected Mattermost versions to apply patches promptly to mitigate the risk of data exposure.

Affected Version(s)

Mattermost 10.4.0 <= 10.4.1

Mattermost 9.11.0 <= 9.11.7

Mattermost 10.3.0 <= 10.3.2

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

visat
.