CVE-2022-25769
Last modified
CVE-2022-25769 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application. This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application. This logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Acquia | Mautic | < 3.3.5 |
| Acquia | Mautic | >= 4.0.0, < 4.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-25769?
How severe is CVE-2022-25769?
How do I fix CVE-2022-25769?
Are you affected by CVE-2022-25769?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
