Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.
History

Thu, 19 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
Description Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.
Title Insufficient authentication in upgrade flow
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mautic

Published: 2024-09-18T21:26:34.059Z

Updated: 2024-09-19T14:47:14.786Z

Reserved: 2022-02-22T20:17:36.804Z

Link: CVE-2022-25770

cve-icon Vulnrichment

Updated: 2024-09-19T14:47:11.083Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-18T22:15:03.827

Modified: 2024-09-20T12:30:17.483

Link: CVE-2022-25770

cve-icon Redhat

No data.