PT-2025-7708 · Mattermost · Mattermost
Visat
·
Published
2025-02-24
·
Updated
2025-03-01
·
CVE-2025-24490
9.6
Critical
Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Mattermost versions 9.11.x through 9.11.7
Mattermost versions 10.2.x through 10.2.2
Mattermost versions 10.3.x through 10.3.2
Mattermost versions 10.4.x through 10.4.1
Description:
The issue allows an attacker to retrieve data from the database via a SQL injection when reordering specially crafted boards categories, due to the failure to use prepared statements in the SQL query of boards reordering.
Recommendations:
For versions 9.11.x through 9.11.7, update to a version that includes the fix for this issue.
For versions 10.2.x through 10.2.2, update to a version that includes the fix for this issue.
For versions 10.3.x through 10.3.2, update to a version that includes the fix for this issue.
For versions 10.4.x through 10.4.1, update to a version that includes the fix for this issue.
Fix
SQL injection
Weakness Enumeration
Related Identifiers
Affected Products
References · 16
- https://bdu.fstec.ru/vul/2025-09051 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-24490 · Security Note
- https://twitter.com/cracbot/status/1895428859325293028 · Twitter Post
- https://t.me/pentestingnews/57027 · Telegram Post
- https://twitter.com/CVEnew/status/1893928183898034319 · Twitter Post
- https://twitter.com/fofabot/status/1894222101076480288 · Twitter Post
- https://t.me/latest_high_impact_cve/1871 · Telegram Post
- https://twitter.com/CveFindCom/status/1893927412754170268 · Twitter Post
- https://t.me/cvedetector/18786 · Telegram Post
- https://twitter.com/the_yellow_fall/status/1894207618077659166 · Twitter Post
- https://mattermost.com/security-updates · Note
- https://twitter.com/Dinosn/status/1894241311252787548 · Twitter Post
- https://twitter.com/cybercronai/status/1894040290513535039 · Twitter Post
- https://twitter.com/adriananglin/status/1894295256260108339 · Twitter Post
- https://twitter.com/zoomeye_team/status/1894279111763529950 · Twitter Post