VDB
Sign up
MEDIUM5.5

GHSA-438m-6mhw-hq5w

Mautic vulnerable to secret data extraction via elfinder

Quick fix

GHSA-438m-6mhw-hq5w — mautic/core: upgrade to the fixed version with the command below.

composer require mautic/core:^4.4.17

Details

### Summary _A user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available._

### Impact _An administrator who usually does not have access to certain parameters, such as database credentials, can disclose them._

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mautic/core
Introduced in: 4.4.0Fixed in: 4.4.17
Fixcomposer require mautic/core:^4.4.17
Packagist/mautic/core
Introduced in: 5.0.0-alphaFixed in: 5.2.8
Fixcomposer require mautic/core:^5.2.8
Packagist/mautic/core
Introduced in: 6.0.0-alphaFixed in: 6.0.5
Fixcomposer require mautic/core:^6.0.5

References