CVE-2022-25776: Sensitive Data Exposure due to inadequate user permission settings
Impact Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing.
Users could potentially access sensitive data such as names and surnames, company names and stage names.
Patches Update to 4.4.12 and 5.0.4
Workarounds No
References https://owasp.org/www-project-top-ten/2017/A32017-SensitiveDataExposure
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25776?
The severity of CVE-2022-25776 is considered high due to its potential impact on sensitive data access.
How do I fix CVE-2022-25776?
To fix CVE-2022-25776, you should update Mautic to version 5.0.4 or 4.4.12.
Who is affected by CVE-2022-25776?
Logged in users of Mautic versions prior to 4.4.12 and 5.0.4 are affected by CVE-2022-25776.
What kind of data can be accessed due to CVE-2022-25776?
Due to CVE-2022-25776, users may gain unauthorized access to sensitive information including names, company names, and stage names.
Is there a patch available for CVE-2022-25776?
Yes, patches for CVE-2022-25776 have been released in versions 4.4.12 and 5.0.4 of Mautic.