High severity8.3NVD Advisory· Published Sep 18, 2024· Updated Jun 17, 2026
CVE-2022-25776
CVE-2022-25776
Description
Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing.
Users could potentially access sensitive data such as names and surnames, company names and stage names.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mautic/corePackagist | >= 1.0.2, < 4.4.12 | 4.4.12 |
mautic/corePackagist | >= 5.0.0-alpha, < 5.0.4 | 5.0.4 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-qjx3-2g35-6hv8ghsaADVISORY
- github.com/mautic/mautic/security/advisories/GHSA-qjx3-2g35-6hv8nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-25776ghsaADVISORY
- github.com/mautic/mautic/commit/22bdd0796ca6e1e985708b89ad5c07147630fecdghsaWEB
- github.com/mautic/mautic/commit/2cc4af975fe01c264d439acc1451c936e7114644ghsaWEB
News mentions
0No linked articles in our index yet.