PT-2024-11535 · Mautic · Mautic

·

CVE-2022-25770

·

Published

2024-09-18

·

Updated

2024-09-20

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mautic (affected versions not specified)
Description The upgrade logic in Mautic's application update via an upgrade script is not properly shielded, potentially leading to a vulnerable situation. However, this issue is mitigated by the fact that Mautic must be installed in a specific way to be vulnerable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25770
GHSA-5HC5-FXR9-5FRC
GHSA-QF6M-6M4G-RMRC

Affected Products

Mautic