Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2024-47059

Disclosure Date: September 18, 2024 (last updated September 19, 2024)
When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an incorrect username is provided alongside with a weak password, the application responds with ’Invalid credentials’ notification. This difference could be used to perform username enumeration.
0
Attacker Value
Unknown

CVE-2022-25770

Disclosure Date: September 18, 2024 (last updated September 19, 2024)
Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.
0
Attacker Value
Unknown

CVE-2022-25768

Disclosure Date: September 18, 2024 (last updated September 19, 2024)
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of the upgrade process without permission. As upgrading in the user interface is deprecated, this functionality is no longer required.
0
Attacker Value
Unknown

CVE-2022-25777

Disclosure Date: September 18, 2024 (last updated September 19, 2024)
Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability.
0
Attacker Value
Unknown

CVE-2022-25769

Disclosure Date: September 18, 2024 (last updated September 19, 2024)
ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application. This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.
0
Attacker Value
Unknown

CVE-2024-3448

Disclosure Date: April 10, 2024 (last updated April 11, 2024)
Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeAvailability leads to a Server-Side Request Forgery by analyzing the error messages returned from the back-end. Allowing an attacker to perform a port scan in the back-end. At the time of publication of the CVE no patch is available.
0
Attacker Value
Unknown

CVE-2024-2731

Disclosure Date: April 10, 2024 (last updated April 11, 2024)
Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages that expose sensitive information such as company names, users' names and surnames, stage names, and monitoring campaigns and their descriptions. In addition, unprivileged users can see and edit the descriptions of tags. At the time of publication of the CVE no patch is available.
0
Attacker Value
Unknown

CVE-2024-2730

Disclosure Date: April 10, 2024 (last updated April 11, 2024)
Mautic uses predictable page indices for unpublished landing pages, their content can be accessed by unauthenticated users under public preview URLs which could expose sensitive data. At the time of publication of the CVE no patch is available
0
Attacker Value
Unknown

CVE-2020-35129

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally drafted JavaScript file that would allow them to eventually perform actions on the target user’s behalf, including changing the user’s password or email address or changing the attacker’s user role from a low-privileged user to an administrator account.
Attacker Value
Unknown

CVE-2018-8071

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
Mautic before v2.13.0 has stored XSS via a theme config file.
0