Description
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.
Problem types
Product status
>= 4.4.0 before < 4.4.17
>= 5.0.0-alpha before < 5.2.8
>= 6.0.0-alpha before < 6.0.5
Credits
B0D0B0P0T
lenonleite
kuzmany
References
github.com/...mautic/security/advisories/GHSA-438m-6mhw-hq5w