Mautic vulnerable to secret data extraction via elfinder
Package
Affected versions
>= 4.4.0, < 4.4.17
>= 5.0.0-alpha, < 5.2.8
>= 6.0.0-alpha, < 6.0.5
Patched versions
4.4.17
5.2.8
6.0.5
Description
Published by the National Vulnerability Database
Sep 3, 2025
Published to the GitHub Advisory Database
Sep 3, 2025
Reviewed
Sep 3, 2025
Last updated
Sep 3, 2025
Summary
A user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available.
Impact
An administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.
References