CVE-2025-9822 Details
Description
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.
A vulnerability exists in Mautic versions 4.4.0 prior to 4.4.17, 5.0.0-alpha through 5.2.8, and 6.0.0-alpha through 6.0.5. It allows administrators to modify application configurations and access sensitive information, such as database credentials, that is typically restricted.
Users can upgrade to Mautic versions 4.4.17, 5.2.8, or 6.0.5 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 3, 2025CISA-ADP
Assessed Sep 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mautic/mautic/security/advisories/GHSA-438m-6mhw-hq5w | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-283 | Unverified Ownership | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mautic | >= 4.4.0, < 4.4.17 (semver) >= 5.0.0-alpha, < 5.2.8 (semver) >= 6.0.0-alpha, < 6.0.5 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 3, 2025 | New CVE Received | [email protected] |
Volerion