ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application.
This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mautic
Mautic mautic |
|
CPEs | cpe:2.3:a:mautic:mautic:-:*:*:*:*:*:*:* | |
Vendors & Products |
Mautic
Mautic mautic |
|
Metrics |
ssvc
|
Wed, 18 Sep 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application. This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path. | |
Title | Improper regex in htaccess file | |
Weaknesses | CWE-1284 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Mautic
Published: 2024-09-18T14:47:09.029Z
Updated: 2024-09-18T21:28:12.305Z
Reserved: 2022-02-22T20:17:36.804Z
Link: CVE-2022-25769
Vulnrichment
Updated: 2024-09-18T18:12:08.784Z
NVD
Status : Awaiting Analysis
Published: 2024-09-18T15:15:13.060
Modified: 2024-09-20T12:30:17.483
Link: CVE-2022-25769
Redhat
No data.