High severity7.2NVD Advisory· Published Sep 18, 2024· Updated Jun 17, 2026
CVE-2022-25769
CVE-2022-25769
Description
ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application.
This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mautic/corePackagist | < 3.3.5 | 3.3.5 |
mautic/corePackagist | >= 4.0.0, < 4.2.0 | 4.2.0 |
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-mj6m-246h-9w56ghsaADVISORY
- github.com/mautic/mautic/security/advisories/GHSA-mj6m-246h-9w56nvdVendor AdvisoryWEB
- www.mautic.org/blog/community/mautic-4-2-one-small-step-mauticnvdRelease Notes
News mentions
0No linked articles in our index yet.