CVE-2022-25775

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-25775
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-25775.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-25775
Aliases
Published
2024-09-18T15:15:13Z
Modified
2024-10-08T03:50:47.293671Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle.

The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.

References

Affected packages

Git / github.com/mautic/mautic

Affected ranges

Type
GIT
Repo
https://github.com/mautic/mautic
Events

Affected versions

2.*

2.14.1
2.14.2
2.14.2-beta
2.15.0
2.15.1
2.15.1-beta
2.15.2-beta
2.15.3-beta
2.16.0-beta
2.16.2
2.16.2-beta

3.*

3.0.0
3.0.0-8885
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5-rc
3.3.0-rc
3.3.2
3.3.2-rc

4.*

4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9