Record summary

CVE-2025-9821 has a selected CVSS score of 2.7 (low).

Description

SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/  for more potential impact. Resources https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html  for more information on SSRF and its fix.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 3, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Mautic

Browse Mautic / Mauticmautic/core

Default status: unaffected

CVE List>= 4.4.0 to ≤ < 4.4.17affected
>= 5.0.0-alpha to ≤ < 5.2.8affected
>= 6.0.0-alpha to ≤ < 6.0.5affected
GitHub Advisory4.4.0 to < 4.4.17 · Fixed in 4.4.17affected
5.0.0-alpha to < 5.2.8 · Fixed in 5.2.8affected
6.0.0-alpha to < 6.0.5 · Fixed in 6.0.5affected

References

5