Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reordering specially crafted boards categories.
The vulnerability results from the lack of prepared statements in the SQL query responsible for changing the order of arrays. An authenticated attacker can send specially crafted input when changing the order of board categories, allowing SQL code injection. As a result, the server executes unintended database queries, exposing its contents.
An attacker can read arbitrary data from the Mattermost database, including potentially user data, messages, and configurations. The vulnerability has a changed scope (Scope Changed), which means it can affect beyond the direct application context.
Mattermost Server should be updated to versions higher than: 10.4.1, 10.3.2, 10.2.2, or 9.11.7. Detailed information about available patches is available at https://mattermost.com/security-updates
Mattermost Server in versions: 10.4.x <= 10.4.1, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2, 9.11.x <= 9.11.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NMattermost Server
APPMattermost9.11.0 – 9.11.8 (excl.)10.2.0 – 10.2.3 (excl.)10.3.0 – 10.3.3 (excl.)10.4.0 – 10.4.2 (excl.)
Related vulnerabilities
Mattermost Server: przejęcie konta przez błędną walidację OAuth state token
Mattermost Server — przejęcie konta przez błąd weryfikacji tokenu OAuth (account takeover)
Mattermost Server: path traversal w ekstraktorze archiwów umożliwia RCE
Mattermost Server — path traversal przy imporcie tablic (Boards)
Mattermost Server: path traversal przy duplikowaniu bloków w Boards