GHSA-vph5-ghq3-q782

Suggest an improvement
Source
https://github.com/advisories/GHSA-vph5-ghq3-q782
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-vph5-ghq3-q782/GHSA-vph5-ghq3-q782.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vph5-ghq3-q782
Aliases
  • CVE-2024-47055
Published
2025-05-28T17:38:58Z
Modified
2025-05-28T20:46:26.191298Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Mautic segment cloning doesn't have a proper permission check
Details

Summary

This advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks.

Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the cloneAction of the segment management. This allows an authenticated user to bypass intended permission restrictions and clone segments even if they lack the necessary permissions to create new ones.

Mitigation

Update Mautic to a version that implements proper authorization checks for the cloneAction within the ListController.php. Ensure that users attempting to clone segments possess the appropriate creation permissions.

Workarounds

None

If you have any questions or comments about this advisory: Email us at security@mautic.org

Database specific
{
    "nvd_published_at": "2025-05-28T18:15:24Z",
    "cwe_ids": [
        "CWE-284",
        "CWE-862"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-05-28T17:38:58Z"
}
References

Affected packages

Packagist / mautic/core

Package

Name
mautic/core
Purl
pkg:composer/mautic/core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0-alpha
Fixed
5.2.6

Affected versions

5.*

5.0.0-alpha
5.0.0-alpha1
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.0-rc2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5

Packagist / mautic/core

Package

Name
mautic/core
Purl
pkg:composer/mautic/core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0-alpha
Fixed
6.0.2

Affected versions

6.*

6.0.0-alpha
6.0.0-beta2
6.0.0-rc
6.0.0
6.0.1