SQL Injection Vulnerability in Mattermost Project Management Software
CVE-2025-24490
What is CVE-2025-24490?
Certain versions of Mattermost are vulnerable to SQL injection due to the improper use of prepared statements in the SQL query responsible for reordering boards. This flaw allows attackers to craft specific requests that can potentially retrieve sensitive data from the database, compromising the confidentiality and integrity of the information stored. It is crucial for users of affected Mattermost versions to apply patches promptly to mitigate the risk of data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 10.4.0 <= 10.4.1
Mattermost 9.11.0 <= 9.11.7
Mattermost 10.3.0 <= 10.3.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved