Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.
History

Wed, 18 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Mautic
Mautic mautic
CPEs cpe:2.3:a:mautic:mautic:-:*:*:*:*:*:*:*
Vendors & Products Mautic
Mautic mautic
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 15:15:00 +0000

Type Values Removed Values Added
Description Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.
Title SQL Injection in dynamic Reports
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mautic

Published: 2024-09-18T15:01:23.529Z

Updated: 2024-09-18T21:30:23.104Z

Reserved: 2022-02-22T20:17:36.805Z

Link: CVE-2022-25775

cve-icon Vulnrichment

Updated: 2024-09-18T17:47:27.121Z

cve-icon NVD

Status : Received

Published: 2024-09-18T15:15:13.440

Modified: 2024-09-18T15:15:13.440

Link: CVE-2022-25775

cve-icon Redhat

No data.