Description

Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 19, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Mautic

Browse Mautic / Mauticmautic/core-lib

Default status: unaffected

CVE List>= 1.0.0-beta3 to < < 4.4.13affected
>= 5.0.0 to < < 5.1.1.affected
GitHub Advisory1.0.0-beta3 to < 4.4.13 · Fixed in 4.4.13affected
5.0.0-alpha to < 5.1.1 · Fixed in 5.1.1affected
GitHub Advisory1.0.0-beta3 to < 4.4.13 · Fixed in 4.4.13affected
5.0.0-alpha to < 5.1.1 · Fixed in 5.1.1affected

References

5