CVE-2017-1000490

Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
acquiamautic
1.0.1
acquiamautic
1.0.2
acquiamautic
1.0.3
acquiamautic
1.0.4
acquiamautic
1.0.5
acquiamautic
1.1.0
acquiamautic
1.1.1
acquiamautic
1.1.2
acquiamautic
1.1.3
acquiamautic
1.2.0:beta1
acquiamautic
1.2.1
acquiamautic
1.2.2
acquiamautic
1.2.3
acquiamautic
1.2.4
acquiamautic
1.3.0
acquiamautic
1.3.1
acquiamautic
1.4.0
acquiamautic
1.4.1
acquiamautic
2.0.0
acquiamautic
2.0.1
acquiamautic
2.1.0
acquiamautic
2.1.1
acquiamautic
2.2.0
acquiamautic
2.2.1
acquiamautic
2.3.0
acquiamautic
2.4.0
acquiamautic
2.5.0
acquiamautic
2.5.1
acquiamautic
2.6.0
acquiamautic
2.6.1
acquiamautic
2.7.0
acquiamautic
2.7.1
acquiamautic
2.8.0
acquiamautic
2.8.1
acquiamautic
2.8.2
acquiamautic
2.9.0:beta
acquiamautic
2.9.1
acquiamautic
2.10.0:beta
acquiamautic
2.10.1
acquiamautic
2.11.0:beta
mauticmautic
1.0.0
mauticmautic
1.2.0
mauticmautic
2.9.0
mauticmautic
2.9.2
mauticmautic
2.10.0
mauticmautic
2.11.0
𝑥
= Vulnerable software versions