Mautic
cpe:2.3:a:mautic:mautic:*:*:*:*:*:*:*
- >= 4.4.0, < 4.4.17
- >= 5.0.0-alpha, < 5.2.8
- >= 6.0.0-alpha, < 6.0.5
A server-side request forgery (SSRF) vulnerability has been identified in Mautic's webhook functionality, affecting versions 4.4.0 prior to 4.4.17, 5.0.0-alpha prior to 5.2.8, and 6.0.0-alpha prior to 6.0.5. This vulnerability allows users with webhook permissions to send requests to internal services by exploiting unvalidated webhook destinations. Additionally, if these users can access webhook logs, they may receive partial responses from the requests, potentially disclosing sensitive information.
Exploitation of this vulnerability could bypass firewalls and allow interaction with internal services, creating risks associated with unauthorized access or manipulation of those services.
Users can update to Mautic versions 4.4.17, 5.2.8, or 6.0.5 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.