ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application.
This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.
References
| Link | Resource |
|---|---|
| https://github.com/mautic/mautic/security/advisories/GHSA-mj6m-246h-9w56 | Vendor Advisory |
| https://www.mautic.org/blog/community/mautic-4-2-one-small-step-mautic | Release Notes |
Configurations
Configuration 1 (hide)
|
History
17 Jun 2026, 04:34
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:* | |
| First Time |
Acquia
Acquia mautic |
|
| References | () https://github.com/mautic/mautic/security/advisories/GHSA-mj6m-246h-9w56 - Vendor Advisory | |
| References | () https://www.mautic.org/blog/community/mautic-4-2-one-small-step-mautic - Release Notes |
20 Sep 2024, 12:30
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
18 Sep 2024, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-09-18 15:15
Updated : 2026-06-17 04:34
NVD link : CVE-2022-25769
Mitre link : CVE-2022-25769
CVE.ORG link : CVE-2022-25769
JSON object : View
Products Affected
acquia
- mautic
CWE
CWE-1284
Improper Validation of Specified Quantity in Input
