CVE-2022-25773 - CVE House
Back to Database
Status published Medium CVE-2022-25773

Relative Path Traversal in assets file upload

Vulnerability Description

This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server. * Improper Limitation of a Pathname to a Restricted Directory: A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-25773

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Patryk Gruzska
  • Majkelstick
  • John Linhart
  • Lenon Leite

Affected Vendor

Affected Software

mautic/core
Vulnerable Versions:
< 5.2.3

Timeline

Official Publish: February 26th, 2025
Last Modified: March 12th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)