CVE-2025-9822: Secret data extraction via elfinder
Summary A user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available.
Impact An administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.
Other sources
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available.
ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9822?
CVE-2025-9822 is considered a high-severity vulnerability due to its potential to expose sensitive secrets to unauthorized administrators.
How do I fix CVE-2025-9822?
To fix CVE-2025-9822, ensure that proper access controls are enforced for user permissions within the Mautic application.
Who is affected by CVE-2025-9822?
CVE-2025-9822 affects Mautic installations where administrators can change configurations and access sensitive data.
What are the risks associated with CVE-2025-9822?
The risks associated with CVE-2025-9822 include unauthorized disclosure of sensitive database credentials and other secret configurations.
What exploit methods are possible with CVE-2025-9822?
Possible exploit methods for CVE-2025-9822 involve manipulating administrator configurations to access hidden parameters and sensitive secrets.