PT-2024-11538 · Mautic · Mautic

Avikarsha Saha

+5

·

Published

2024-04-12

·

Updated

2024-09-24

·

CVE-2022-25776

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions Mautic versions prior to 4.4.12 Mautic versions prior to 5.0.4
Description Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names.
Recommendations Update to version 4.4.12 to resolve the issue for versions prior to 4.4.12. Update to version 5.0.4 to resolve the issue for versions prior to 5.0.4.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2022-25776
GHSA-QJX3-2G35-6HV8

Affected Products

Mautic