icon

We found results for “

CVE-2022-25777

Good to know:

icon

Date: September 18, 2024

Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability.

Severity Score

Severity Score

Weakness Type (CWE)

Server-Side Request Forgery (SSRF)

CWE-918

Top Fix

icon

Upgrade Version

Upgrade to version mautic/core - dev-progresive-profiling-company-fields;mautic/core - dev-all-contributors/add-exsesx;mautic/core - dev-dependabot/npm_and_yarn/micromatch-4.0.8;mautic/core - dev-bump-4.4.3;mautic/core - dev-test-codecov-4.0;mautic/core - dev-bump-4.4.4;mautic/core - dev-generate-release-notes;mautic/core - dev-updating-artifacts;mautic/core - dev-fix-company-import-error-without-unique-field;mautic/core - dev-fix-issue-template;mautic/core - dev-fix/update-french-regions;mautic/core - dev-all-contributors/add-laurielim;mautic/core - dev-update-GitHub-actions-support-queue;mautic/core - dev-dependabot/npm_and_yarn/braces-3.0.3;mautic/core - dev-all-contributors/add-domparry;mautic/core - dev-all-contributors/add-dsp76;mautic/core - dev-create-pull-request/patch;mautic/core - dev-phpstan-baseline;mautic/core - dev-sms-token-support-5x;mautic/core - dev-fix-clean-sync_object_field_change_report_after_delete;mautic/core - dev-all-contributors/add-putzwasser;mautic/core - dev-guide_user_to_build_optimized_segment;mautic/core - dev-dependabot/composer/guzzlehttp/psr7-2.5.0;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/multi-bc20d10cf2;mautic/core - dev-git-subtree-4.0;mautic/core - dev-add-allow-redirect-in-download-request;mautic/core - dev-bump-4.4.5;mautic/core - dev-remove-pending-count;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/underscore-and-backbone-undo-1.13.1;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/browserify-sign-4.2.2;mautic/core - dev-staging3.0.x-include-exclude-for-text-field;mautic/core - dev-email-draft-feature;mautic/core - dev-all-contributors/add-rohitpavaskar;mautic/core - dev-add-refactoring-release-notes;mautic/core - 4.4.12;mautic/core - 1.3.1;mautic/core - dev-fix_10531;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/ansi-regex-5.0.1;mautic/core - dev-fix-campaign-loop-jump-action;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/async-3.2.3;mautic/core - dev-add_messenger;mautic/core - dev-fix-ddev;mautic/core - dev-change-template-email-trans-2;mautic/core - dev-remove-mautibox-reference-4.1;mautic/core - dev-all-contributors/add-AlanWierzchonCA;mautic/core - dev-feature/add-more-info-in-tooltip;mautic/core - dev-all-contributors/add-KN4CK3R;mautic/core - dev-update-license;mautic/core - dev-Improve-issue-template;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/minimatch-3.1.2;mautic/core - dev-all-contributors/add-disha-pishavadia24;mautic/core - dev-all-contributors/add-Christophe9880;mautic/core - dev-all-contributors/add-bradycargle;mautic/core - dev-add-created-modified-date-contact-profile;mautic/core - dev-dependabot/composer/twig/twig-3.3.8;mautic/core - dev-bump-4.0.2-rc;mautic/core - 5.x-dev;mautic/core - dev-fix-best-hours-widget;mautic/core - dev-update-stalebot;mautic/core - dev-fix-assetshelper-on-installation;mautic/core - dev-Fix_ActivityListType_array_flip;mautic/core - dev-all-contributors/add-oltmanns-leuchtfeuer;mautic/core - dev-dennisameling-patch-1;mautic/core - dev-TPROD-385;mautic/core - dev-fix/category-locked;mautic/core - dev-all-contributors/add-RehanNischal;mautic/core - dev-fix-unhide;mautic/core - dev-revert-12818-ddev-config-update;mautic/core - dev-all-contributors/add-giomasce;mautic/core - dev-all-contributors/add-vinzent;mautic/core - dev-stop-duplicate-campaign-update;mautic/core - 5.0.4;mautic/core-lib - 4.0.x-dev;mautic/core-lib - 4.3.0-beta;mautic/core-lib - 4.2.1;mautic/core-lib - 4.2.0;mautic/core-lib - 4.4.12;mautic/core-lib - 5.0.4;mautic/core-lib - 5.x-dev;mautic/core-lib - dev-gitsplit-action-debug

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us