github.com
https://github.com/mautic/mautic CVE-2025-9822
MEDIUM
Secret data extraction via elfinder
Record summary
CVE-2025-9822 has a selected CVSS score of 5.5 (medium).
Description
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 3, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | >= 4.4.0 to < < 4.4.17 | affected |
| >= 5.0.0-alpha to < < 5.2.8 | affected | ||
| >= 6.0.0-alpha to < < 6.0.5 | affected | ||
mautic/coreBrowse Packagist / mautic/core | GitHub Advisory | 4.4.0 to < 4.4.17 · Fixed in 4.4.17 | affected |
| 5.0.0-alpha to < 5.2.8 · Fixed in 5.2.8 | affected | ||
| 6.0.0-alpha to < 6.0.5 · Fixed in 6.0.5 | affected |
References
5github.com
https://github.com/mautic/mautic/commit/882c2c5be646e36f7b91e7c4b24f71aafa617cd5 github.com
https://github.com/mautic/mautic/commit/a310b1933de7cfefec03382a4d8c0d9dbbaa0600 github.com
https://github.com/mautic/mautic/security/advisories/GHSA-438m-6mhw-hq5w nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-9822