Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/mattermost-community/focalboard |
|
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to sanitize category IDs before incorporating them into dynamic SQL statements when reordering categories. An attacker can inject a malicious SQL payload into the category id field, which is stored in the database and later executed unsanitized when the category reorder API processes the stored value. This Second-Order SQL Injection (Time-Based Blind) allows an authenticated attacker to exfiltrate sensitive data including password hashes of other users. NOTE: Focalboard as a standalone product is not maintained and no fix will be issued. | |
| Title | Focalboard Second-Order SQL Injection in category reorder endpoint allows data exfiltration (unsupported product, no fix) | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-04-03T14:57:00.729Z
Reserved: 2026-04-03T13:10:59.186Z
Link: CVE-2026-25773
Updated: 2026-04-03T14:56:50.635Z
Status : Awaiting Analysis
Published: 2026-04-03T14:16:29.127
Modified: 2026-04-03T16:10:23.730
Link: CVE-2026-25773
No data.
OpenCVE Enrichment
No data.