CVE-2022-25775

Source
https://cve.org/CVERecord?id=CVE-2022-25775
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-25775.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-25775
Aliases
Published
2024-09-18T15:15:13.440Z
Modified
2026-02-03T07:32:46.008741Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle.

The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.

References

Affected packages

Git / github.com/mautic/mautic

Affected versions

2.*
2.14.1
2.14.2
2.14.2-beta
2.15.0
2.15.1
2.15.1-beta
2.15.2-beta
2.15.3-beta
2.16.0-beta
2.16.2
2.16.2-beta
3.*
3.0.0
3.0.0-8885
3.0.0-alpha
3.0.0-beta
3.0.0-beta2
3.0.1
3.0.2
3.0.2-rc
3.1.0
3.1.0-rc
3.1.1
3.1.1-rc
3.1.2
3.1.2-rc
3.2.0
3.2.0-rc
3.2.1
3.2.2
3.2.2-rc
3.2.3
3.2.4
3.2.5-rc
3.3.0-rc
3.3.2
3.3.2-rc
4.*
4.0.0
4.0.0-alpha1
4.0.0-beta
4.0.0-rc
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.0-beta
4.3.0-rc
4.3.1
4.4.0
4.4.0-beta
4.4.1
4.4.10
4.4.11
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
5.*
5.0.0
5.0.1
5.0.2
5.0.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-25775.json"