CVE-2022-25775

Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:*
cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-18 15:15

Updated : 2024-09-23 23:22


NVD link : CVE-2022-25775

Mitre link : CVE-2022-25775

CVE.ORG link : CVE-2022-25775


JSON object : View

Products Affected

acquia

  • mautic
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')