CVE-2022-25769

HIGH

Apache - Info Disclosure

Title source: llm
STIX 2.1

Description

ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application. This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.

Scores

CVSS v3 7.2
EPSS 0.0012
EPSS Percentile 30.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1284
Status published
Products (2)
acquia/mautic < 3.3.5
mautic/core 0 - 3.3.5Packagist
Published Sep 18, 2024
Tracked Since Feb 18, 2026