Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-25775


Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.


Published

2024-09-18T15:15:13.440

Last Modified

2024-09-23T23:22:15.763

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.6 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-89
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application acquia mautic < 4.4.12 Yes
Application acquia mautic < 5.0.4 Yes

References