Mautic allows you to update the application via an upgrade script.
The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation.
This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.
References
Link | Resource |
---|---|
https://github.com/mautic/mautic/security/advisories/GHSA-qf6m-6m4g-rmrc | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
27 Feb 2025, 19:30
Type | Values Removed | Values Added |
---|---|---|
First Time |
Acquia mautic
Acquia |
|
References | () https://github.com/mautic/mautic/security/advisories/GHSA-qf6m-6m4g-rmrc - Vendor Advisory | |
CPE | cpe:2.3:a:acquia:mautic:1.0.0:beta3:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:rc1:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:rc4:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:rc3:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:rc2:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:-:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:beta4:*:*:*:*:*:* |
20 Sep 2024, 12:30
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
18 Sep 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-18 22:15
Updated : 2025-02-27 19:30
NVD link : CVE-2022-25770
Mitre link : CVE-2022-25770
CVE.ORG link : CVE-2022-25770
JSON object : View
Products Affected
acquia
- mautic
CWE
CWE-306
Missing Authentication for Critical Function