CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-24490

CVSS 9.6v3.1pub. 2025-02-24upd. 2025-10-01

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reordering specially crafted boards categories.

🤖 AI Analysis
How it works

The vulnerability results from the lack of prepared statements in the SQL query responsible for changing the order of arrays. An authenticated attacker can send specially crafted input when changing the order of board categories, allowing SQL code injection. As a result, the server executes unintended database queries, exposing its contents.

Impact

An attacker can read arbitrary data from the Mattermost database, including potentially user data, messages, and configurations. The vulnerability has a changed scope (Scope Changed), which means it can affect beyond the direct application context.

Mitigation & patch

Mattermost Server should be updated to versions higher than: 10.4.1, 10.3.2, 10.2.2, or 9.11.7. Detailed information about available patches is available at https://mattermost.com/security-updates

Who is affected

Mattermost Server in versions: 10.4.x <= 10.4.1, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2, 9.11.x <= 9.11.7

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Mattermost Server

    APP
    Mattermost
    9.11.0 – 9.11.8 (excl.)10.2.0 – 10.2.3 (excl.)10.3.0 – 10.3.3 (excl.)10.4.0 – 10.4.2 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-12419CRITICAL9.9PL ✓same product

Mattermost Server: przejęcie konta przez błędną walidację OAuth state token

CVE-2025-12421CRITICAL9.9PL ✓same product

Mattermost Server — przejęcie konta przez błąd weryfikacji tokenu OAuth (account takeover)

CVE-2025-4981CRITICAL9.9PL ✓same product

Mattermost Server: path traversal w ekstraktorze archiwów umożliwia RCE

CVE-2025-25279CRITICAL9.9PL ✓same product

Mattermost Server — path traversal przy imporcie tablic (Boards)

CVE-2025-20051CRITICAL9.9PL ✓same product

Mattermost Server: path traversal przy duplikowaniu bloków w Boards