Mautic
cpe:2.3:a:mautic:mautic:*:*:*:*:*:*:*
- >= 4.4.0, < 4.4.17
- >= 5.0.0-alpha, < 5.2.8
- >= 6.0.0-alpha, < 6.0.5
A vulnerability exists in Mautic versions 4.4.0 prior to 4.4.17, 5.0.0-alpha through 5.2.8, and 6.0.0-alpha through 6.0.5. It allows administrators to modify application configurations and access sensitive information, such as database credentials, that is typically restricted.
Exploitation of this vulnerability enables unauthorized disclosure of confidential data, including database credentials, to administrators who would not normally have access to such information.
Users can upgrade to Mautic versions 4.4.17, 5.2.8, or 6.0.5 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.