CVE-2025-9822

Source
https://cve.org/CVERecord?id=CVE-2025-9822
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9822.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-9822
Aliases
Published
2025-09-03T13:55:12Z
Modified
2026-08-12T03:51:22Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
Secret data extraction via elfinder
Details

SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available.

ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.

Database specific
{
    "cna_assigner": "Mautic",
    "cwe_ids": [
        "CWE-283"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9822.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": ">= 4.4.0"
                },
                {
                    "fixed": "< 4.4.17"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/mautic/mautic

Affected ranges

Type
GIT
Repo
https://github.com/mautic/mautic
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": ">= 5.0.0-alpha"
        },
        {
            "fixed": "< 5.2.8"
        },
        {
            "introduced": ">= 6.0.0-alpha"
        },
        {
            "fixed": "< 6.0.5"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

5.*
5.0.0
5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
6.*
6.0.0
6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.1
6.0.2
6.0.3
6.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9822.json"