SB2025062304 - Multiple vulnerabilities in Mautic



SB2025062304 - Multiple vulnerabilities in Mautic

Published: June 23, 2025

Security Bulletin ID SB2025062304
Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 80% Low 20%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 secuirty vulnerabilities.


1) Cleartext storage of sensitive information (CVE-ID: CVE-2024-47056)

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected application does not shield .env files from web traffic. A local attacker can gain access to secret information.


2) Open redirect (CVE-ID: CVE-2025-5256)

The vulnerability allows a remote attacker to redirect victims to arbitrary URL.

The vulnerability exists due to improper sanitization of user-supplied data in user unlocking endpoint within "returnUrl" parameter. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain.

Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.


3) Improper access control (CVE-ID: CVE-2024-47055)

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in the "cloneAction" of the segment management. A remote user can bypass implemented security restrictions and clone segments without proper authorization checks.


4) Observable Response Discrepancy (CVE-ID: CVE-2024-47057)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to response time difference on password reset form within the "Forget your password" functionality. A remote attacker can enumerate valid usernames.


5) Improper access control (CVE-ID: CVE-2025-5257)

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to predictable page indexing. A remote attacker can bypass implemented security restrictions and gain unauthorized access to sensitive information.


Remediation

Install update from vendor's website.