Skip to content

Mautic users able to download any files from server using filemanager

High
RCheesley published GHSA-qpgw-2c72-4c89 Jan 19, 2021

Package

composer mautic/core (Composer)

Affected versions

1.0-2.11.0

Patched versions

2.12.0

Description

Impact

Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to.

Patches

Update to 2.12.0 or later.

Workarounds

None

References

https://github.com/mautic/mautic/releases/tag/2.12.0

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2017-1000490

Weaknesses

No CWEs