PT-2025-23102 · Mautic · Mautic

John Linhart

+2

·

Published

2025-05-28

·

Updated

2025-05-30

·

CVE-2025-5257

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Mautic (affected versions not specified)
Description The issue concerns unauthorized access to unpublished page previews in Mautic, which could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. The page preview functionality for unpublished content, accessible via predictable URLs (e.g., "/page/preview/1", "/page/preview/2"), lacked proper authorization checks, allowing any unauthenticated user to view content not yet intended for public release.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-5257
GHSA-CQX4-9VQF-Q3M8

Affected Products

Mautic