CVE-2022-25773

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
26/02/2025
Last modified:
16/10/2025

Description

This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.<br /> <br /> * Improper Limitation of a Pathname to a Restricted Directory: A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:* 5.2.3 (excluding)