GHSA-vph5-ghq3-q782
Mautic segment cloning doesn't have a proper permission check
Quick fix
GHSA-vph5-ghq3-q782 — mautic/core: upgrade to the fixed version with the command below.
composer require mautic/core:^5.2.6Details
### Summary This advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks.
Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the `cloneAction` of the segment management. This allows an authenticated user to bypass intended permission restrictions and clone segments even if they lack the necessary permissions to create new ones.
### Mitigation Update Mautic to a version that implements proper authorization checks for the `cloneAction` within the `ListController.php`. Ensure that users attempting to clone segments possess the appropriate creation permissions.
### Workarounds None
If you have any questions or comments about this advisory: Email us at security@mautic.org
Are you affected?
Enter the version of the package you're using.
Affected packages
5.0.0-alphaFixed in: 5.2.6composer require mautic/core:^5.2.66.0.0-alphaFixed in: 6.0.2composer require mautic/core:^6.0.2