Vulnerability Description
This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server. * Improper Limitation of a Pathname to a Restricted Directory: A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Acquia | Mautic | < 5.2.3 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2022-25773?
CVE-2022-25773 is a vulnerability with a CVSS score of 4.3 (MEDIUM). This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server. * Improper Limitation of a Pathname to a Restricted Directory...
How severe is CVE-2022-25773?
CVE-2022-25773 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25773?
Check the references section above for vendor advisories and patch information. Affected products include: Acquia Mautic.