← Back

CVE-2022-25769

nvd nist
Published: Sep 18, 2024Modified: Feb 27, 2025

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application. This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.

Affected (2)

Products: Acquia: Mautic
1 product
Mautic
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Acquia
Before 3.3.5
From 4.0.0 to 4.2.0

References (2)

Timeline

No history available yet.