Relative Path Traversal in assets file upload
Vulnerability Description
This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server. * Improper Limitation of a Pathname to a Restricted Directory: A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-25773
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Patryk Gruzska
- Majkelstick
- John Linhart
- Lenon Leite
More from Mautic
View All →Affected Vendor
Mautic
View all reports →