PT-2026-44820 · Mautic · Mautic
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mautic versions 7.0.0 through 7.1.1
Description
A path traversal flaw exists in the campaign import feature. During the extraction of uploaded ZIP files, a validation error allows file paths to exit the designated temporary directories. An authenticated user with
campaign:imports:create privileges can write arbitrary PHP files to sensitive system directories, potentially overwriting internal configuration or cache components. This can lead to Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a remote machine, under the context of the web server user.Recommendations
Update to version 7.1.2.
Revoke
campaign:imports:create permissions from non-administrative users.Exploit
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mautic