CVE-2022-25770

Source
https://cve.org/CVERecord?id=CVE-2022-25770
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-25770.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-25770
Aliases
Published
2024-09-18T21:26:34.059Z
Modified
2026-07-15T02:06:00.342384695Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H CVSS Calculator
Summary
Insufficient authentication in upgrade flow
Details

Mautic allows you to update the application via an upgrade script.

The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation.

This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.

Database specific
{
    "cna_assigner": "Mautic",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25770.json",
    "cwe_ids": [
        "CWE-306"
    ]
}
References

Affected packages

Git / github.com/mautic/mautic

Affected ranges

Type
GIT
Repo
https://github.com/mautic/mautic
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:acquia:mautic:1.0.0:-:*:*:*:*:*:*",
        "cpe:2.3:a:acquia:mautic:1.0.0:beta3:*:*:*:*:*:*",
        "cpe:2.3:a:acquia:mautic:1.0.0:beta4:*:*:*:*:*:*",
        "cpe:2.3:a:acquia:mautic:1.0.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:acquia:mautic:1.0.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:acquia:mautic:1.0.0:rc3:*:*:*:*:*:*",
        "cpe:2.3:a:acquia:mautic:1.0.0:rc4:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "1.0.1"
        },
        {
            "fixed": "4.4.13"
        },
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.1.1"
        },
        {
            "introduced": "1.0.0-NA"
        },
        {
            "last_affected": "1.0.0-NA"
        },
        {
            "introduced": "1.0.0-beta3"
        },
        {
            "last_affected": "1.0.0-beta3"
        },
        {
            "introduced": "1.0.0-beta4"
        },
        {
            "last_affected": "1.0.0-beta4"
        },
        {
            "introduced": "1.0.0-rc1"
        },
        {
            "last_affected": "1.0.0-rc1"
        },
        {
            "introduced": "1.0.0-rc2"
        },
        {
            "last_affected": "1.0.0-rc2"
        },
        {
            "introduced": "1.0.0-rc3"
        },
        {
            "last_affected": "1.0.0-rc3"
        },
        {
            "introduced": "1.0.0-rc4"
        },
        {
            "last_affected": "1.0.0-rc4"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

1.*
1.0.0-NA
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.4.1
2.*
2.0.0
2.0.1
2.1.0
2.1.1
2.12.2-beta
2.14.2-beta
2.2.0
2.2.1
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
3.*
3.0.1
3.1.0
3.1.0-rc
3.3.0-rc
4.*
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.1.0
4.2.0
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.12
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.*
5.0.0
5.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-25770.json"