CVE-2022-25777: Server-Side Request Forgery in Asset section
Impact Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability.
Patches Update to 4.4.12 or 5.0.4
Workarounds None
References - https://owasp.org/Top10/A102021-Server-SideRequestForgery%28SSRF%29/
If you have any questions or comments about this advisory:
Email us at security@mautic.org
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25777?
CVE-2022-25777 is classified with a moderate severity due to the risk of unauthorized access to system files.
How do I fix CVE-2022-25777?
To fix CVE-2022-25777, you should update Mautic to version 4.4.12 or 5.0.4.
What type of vulnerability is CVE-2022-25777?
CVE-2022-25777 is a Server-Side Request Forgery (SSRF) vulnerability.
Can CVE-2022-25777 be exploited by unauthenticated users?
No, CVE-2022-25777 can only be exploited by authenticated users of Mautic.
What are the consequences of CVE-2022-25777?
Exploitation of CVE-2022-25777 allows an authenticated user to read sensitive system files and access internal addresses.