Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qf6m-6m4g-rmrc

Опубликовано: 18 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 7.8

Описание

Mautic has insufficient authentication in upgrade flow

Impact

Mautic allows you to update the application via an upgrade script.

The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation.

This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable

Patches

Please upgrade to 4.4.1 or 5.1.1 or later.

Workarounds

None.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 1.0.0-beta3, < 4.4.13

4.4.13

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 5.0.0-alpha, < 5.1.1

5.1.1

Наименование

mautic/core-lib

composer
Затронутые версииВерсия исправления

>= 1.0.0-beta3, < 4.4.13

4.4.13

Наименование

mautic/core-lib

composer
Затронутые версииВерсия исправления

>= 5.0.0-alpha, < 5.1.1

5.1.1

EPSS

Процентиль: 53%
0.00296
Низкий

5.1 Medium

CVSS4

7.8 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.8
nvd
больше 1 года назад

Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.

EPSS

Процентиль: 53%
0.00296
Низкий

5.1 Medium

CVSS4

7.8 High

CVSS3

Дефекты

CWE-306