7.8

CVE-2022-25770

Mautic allows you to update the application via an upgrade script.

The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation.

This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.

Data is provided by the National Vulnerability Database (NVD)
AcquiaMautic Version >= 1.0.1 < 4.4.13
AcquiaMautic Version >= 5.0.0 < 5.1.1
AcquiaMautic Version1.0.0 Update-
AcquiaMautic Version1.0.0 Updatebeta3
AcquiaMautic Version1.0.0 Updatebeta4
AcquiaMautic Version1.0.0 Updaterc1
AcquiaMautic Version1.0.0 Updaterc2
AcquiaMautic Version1.0.0 Updaterc3
AcquiaMautic Version1.0.0 Updaterc4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.309
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
security@mautic.org 7.8 1.4 5.8
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.