SQL Injection Vulnerability in Mattermost Project Management Software
CVE-2025-24490
9.6CRITICAL
What is CVE-2025-24490?
Certain versions of Mattermost are vulnerable to SQL injection due to the improper use of prepared statements in the SQL query responsible for reordering boards. This flaw allows attackers to craft specific requests that can potentially retrieve sensitive data from the database, compromising the confidentiality and integrity of the information stored. It is crucial for users of affected Mattermost versions to apply patches promptly to mitigate the risk of data exposure.
Affected Version(s)
Mattermost 10.4.0 <= 10.4.1
Mattermost 9.11.0 <= 9.11.7
Mattermost 10.3.0 <= 10.3.2