PT-2025-36607 · Packagist · Mautic/Core
Published
2025-09-03
·
Updated
2025-09-03
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N |
Summary
A user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available.
Impact
An administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mautic/Core