Vulnerability record · CVE-2022-25769 · published 18 September 2024
CVE-2022-25769: Acquia mautic vulnerability
AAcquia · Mautic
ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application. This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.
Description
ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application. This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/mautic/mautic/security/advisories/GHSA-mj6m-246h-9w56 | Vendor Advisory |
| https://www.mautic.org/blog/community/mautic-4-2-one-small-step-mautic | Release Notes |
Track CVE-2022-25769 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-25769), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.