High severity7.8NVD Advisory· Published Sep 18, 2024· Updated Jun 17, 2026
CVE-2022-25770
CVE-2022-25770
Description
Mautic allows you to update the application via an upgrade script.
The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation.
This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mautic/corePackagist | >= 1.0.0-beta3, < 4.4.13 | 4.4.13 |
mautic/corePackagist | >= 5.0.0-alpha, < 5.1.1 | 5.1.1 |
mautic/core-libPackagist | >= 1.0.0-beta3, < 4.4.13 | 4.4.13 |
mautic/core-libPackagist | >= 5.0.0-alpha, < 5.1.1 | 5.1.1 |
Affected products
11- ghsa-coords2 versions
>= 1.0.0-beta3, < 4.4.13+ 1 more
- (no CPE)range: >= 1.0.0-beta3, < 4.4.13
- (no CPE)range: >= 1.0.0-beta3, < 4.4.13
cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:*range: >=1.0.1,<4.4.13
- cpe:2.3:a:acquia:mautic:1.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:rc4:*:*:*:*:*:*
- (no CPE)range: >= 1.0.0-beta3
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-qf6m-6m4g-rmrcghsaADVISORY
- github.com/mautic/mautic/security/advisories/GHSA-qf6m-6m4g-rmrcnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-25770ghsaADVISORY
- github.com/mautic/mautic/commit/73b18e9a434a28e528fe0e3d03620e7367bdcdcaghsaWEB
- github.com/mautic/mautic/commit/aee7bfb7510a83acf178a7f02da9661c040e9abfghsaWEB
News mentions
0No linked articles in our index yet.