Record summary

CVE-2025-9822 has a selected CVSS score of 5.5 (medium).

Description

SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 3, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Mautic

Browse Mautic / Mauticmautic/core

Default status: unaffected

CVE List>= 4.4.0 to < < 4.4.17affected
>= 5.0.0-alpha to < < 5.2.8affected
>= 6.0.0-alpha to < < 6.0.5affected
GitHub Advisory4.4.0 to < 4.4.17 · Fixed in 4.4.17affected
5.0.0-alpha to < 5.2.8 · Fixed in 5.2.8affected
6.0.0-alpha to < 6.0.5 · Fixed in 6.0.5affected

References

5