CVE-2022-25773: Relative Path Traversal in assets file upload
Summary
This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
Improper Limitation of a Pathname to a Restricted Directory: A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory.
Mitigation
Please update to 5.2.3 or later.
Workarounds
None
References
If you have any questions or comments about this advisory:
Email us at security@mautic.org
Other sources
This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
Improper Limitation of a Pathname to a Restricted Directory: A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25773?
CVE-2022-25773 has a moderate severity rating due to its potential for unauthorized file placement.
How do I fix CVE-2022-25773?
To fix CVE-2022-25773, you should upgrade to Mautic version 5.2.3 or later.
What systems are affected by CVE-2022-25773?
CVE-2022-25773 affects versions of the Mautic core package prior to 5.2.3.
What type of vulnerability is CVE-2022-25773?
CVE-2022-25773 is an improper limitation of pathname to a restricted directory vulnerability.
Can CVE-2022-25773 lead to remote code execution?
While CVE-2022-25773 primarily allows unauthorized file upload, it may lead to remote code execution if exploited.