* Improper Limitation of a Pathname to a Restricted Directory: A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-30417 | This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server. * Improper Limitation of a Pathname to a Restricted Directory: A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory. |
Github GHSA |
GHSA-4w2w-36vm-c8hf | Mautic allows Relative Path Traversal in assets file upload |
Thu, 16 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Acquia
Acquia mautic |
|
| CPEs | cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Acquia
Acquia mautic |
Wed, 12 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Feb 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server. * Improper Limitation of a Pathname to a Restricted Directory: A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory. | |
| Title | Relative Path Traversal in assets file upload | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mautic
Published:
Updated: 2025-03-12T19:51:58.376Z
Reserved: 2022-02-22T20:17:36.805Z
Link: CVE-2022-25773
Updated: 2025-02-26T14:54:17.583Z
Status : Analyzed
Published: 2025-02-26T13:15:32.550
Modified: 2025-10-16T17:08:58.823
Link: CVE-2022-25773
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA