Medium severity6.6NVD Advisory· Published Sep 18, 2024· Updated Jun 17, 2026
CVE-2022-25775
CVE-2022-25775
Description
Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle.
The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mautic/corePackagist | >= 2.14.1, < 4.4.12 | 4.4.12 |
mautic/corePackagist | >= 5.0.0-alpha, < 5.0.4 | 5.0.4 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-jj6w-2cqg-7p94ghsaADVISORY
- github.com/mautic/mautic/security/advisories/GHSA-jj6w-2cqg-7p94nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-25775ghsaADVISORY
- github.com/mautic/mautic/commit/cab65e0acc4f23c4f07c117dee1b69dac5abed3fghsaWEB
- github.com/mautic/mautic/commit/e75b1eea16309588f069169b5882cf53f854dbd8ghsaWEB
News mentions
0No linked articles in our index yet.