Description
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available.
ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.
ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26505 | SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. |
Github GHSA |
GHSA-438m-6mhw-hq5w | Mautic vulnerable to secret data extraction via elfinder |
References
History
Wed, 03 Sep 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mautic
Mautic mautic |
|
| Vendors & Products |
Mautic
Mautic mautic |
Wed, 03 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them. | |
| Title | Secret data extraction via elfinder | |
| Weaknesses | CWE-283 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mautic
Published:
Updated: 2025-09-03T14:09:46.199Z
Reserved: 2025-09-02T08:22:34.513Z
Link: CVE-2025-9822
Updated: 2025-09-03T14:09:33.496Z
Status : Deferred
Published: 2025-09-03T14:15:46.247
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-9822
No data.
OpenCVE Enrichment
Updated: 2025-09-03T19:30:13Z
Weaknesses
EUVD
Github GHSA