VDB
Sign up
MEDIUM4.3

GHSA-4w2w-36vm-c8hf

Mautic allows Relative Path Traversal in assets file upload

Quick fix

GHSA-4w2w-36vm-c8hf — mautic/core: upgrade to the fixed version with the command below.

composer require mautic/core:^5.2.3

Details

### Summary

This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.

* **Improper Limitation of a Pathname to a Restricted Directory:** A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory.

### Mitigation

Please update to 5.2.3 or later.

### Workarounds

None

### References

If you have any questions or comments about this advisory:

Email us at [security@mautic.org](mailto:security@mautic.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mautic/core
Introduced in: 0Fixed in: 5.2.3
Fixcomposer require mautic/core:^5.2.3

References