github.com
https://github.com/mautic/mautic CVE-2022-25770
Insufficient authentication in upgrade flow
Description
Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 19, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | >= 1.0.0-beta3 to < < 4.4.13 | affected |
| >= 5.0.0 to < < 5.1.1. | affected | ||
mautic/coreBrowse Packagist / mautic/core | GitHub Advisory | 1.0.0-beta3 to < 4.4.13 · Fixed in 4.4.13 | affected |
| 5.0.0-alpha to < 5.1.1 · Fixed in 5.1.1 | affected | ||
mautic/core-libBrowse Packagist / mautic/core-lib | GitHub Advisory | 1.0.0-beta3 to < 4.4.13 · Fixed in 4.4.13 | affected |
| 5.0.0-alpha to < 5.1.1 · Fixed in 5.1.1 | affected |
References
5github.com
https://github.com/mautic/mautic/commit/73b18e9a434a28e528fe0e3d03620e7367bdcdca github.com
https://github.com/mautic/mautic/commit/aee7bfb7510a83acf178a7f02da9661c040e9abf github.com
https://github.com/mautic/mautic/security/advisories/GHSA-qf6m-6m4g-rmrc nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-25770