Mautic allows you to update the application via an upgrade script.
The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation.
This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Feb 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Acquia
Acquia mautic |
|
CPEs | cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:-:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:beta3:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:beta4:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:rc1:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:rc2:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:rc3:*:*:*:*:*:* cpe:2.3:a:acquia:mautic:1.0.0:rc4:*:*:*:*:*:* |
|
Vendors & Products |
Acquia
Acquia mautic |
Thu, 19 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 18 Sep 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable. | |
Title | Insufficient authentication in upgrade flow | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Mautic
Published:
Updated: 2024-09-19T14:47:14.786Z
Reserved: 2022-02-22T20:17:36.804Z
Link: CVE-2022-25770

Updated: 2024-09-19T14:47:11.083Z

Status : Analyzed
Published: 2024-09-18T22:15:03.827
Modified: 2025-02-27T19:30:33.180
Link: CVE-2022-25770

No data.