PT-2024-11535 · Mautic · Mautic

John Linhart

+4

·

Published

2024-09-18

·

Updated

2024-09-20

·

CVE-2022-25770

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mautic (affected versions not specified)
Description The upgrade logic in Mautic's application update via an upgrade script is not properly shielded, potentially leading to a vulnerable situation. However, this issue is mitigated by the fact that Mautic must be installed in a specific way to be vulnerable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-25770
GHSA-5HC5-FXR9-5FRC
GHSA-QF6M-6M4G-RMRC

Affected Products

Mautic