Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qjx3-2g35-6hv8

Опубликовано: 12 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.3

Описание

Mautic Sensitive Data Exposure due to inadequate user permission settings

Impact

Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing.

Users could potentially access sensitive data such as names and surnames, company names and stage names.

Patches

Update to 4.4.12 and 5.0.4

Workarounds

No

References

https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure

Пакеты

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 1.0.2, < 4.4.12

4.4.12

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 5.0.0-alpha, < 5.0.4

5.0.4

EPSS

Процентиль: 13%
0.00043
Низкий

8.3 High

CVSS3

Дефекты

CWE-276
CWE-280

Связанные уязвимости

CVSS3: 8.3
nvd
больше 1 года назад

Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names.

EPSS

Процентиль: 13%
0.00043
Низкий

8.3 High

CVSS3

Дефекты

CWE-276
CWE-280