GHSA-4w2w-36vm-c8hf
Mautic allows Relative Path Traversal in assets file upload
Quick fix
GHSA-4w2w-36vm-c8hf — mautic/core: upgrade to the fixed version with the command below.
composer require mautic/core:^5.2.3Details
### Summary
This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
* **Improper Limitation of a Pathname to a Restricted Directory:** A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory.
### Mitigation
Please update to 5.2.3 or later.
### Workarounds
None
### References
If you have any questions or comments about this advisory:
Email us at [security@mautic.org](mailto:security@mautic.org)
Are you affected?
Enter the version of the package you're using.