Insufficient authentication in upgrade flow
Vulnerability Description
Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-25770
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Mattias Michaux
- Zdeno Kuzmany
- Mattias Michaux
- John Linhart
- Patryk Gruszka
More from Mautic
View All →Affected Vendor
Mautic
View all reports →