Mautic allows Relative Path Traversal in assets file upload
Description
Published by the National Vulnerability Database
Feb 26, 2025
Published to the GitHub Advisory Database
Feb 26, 2025
Reviewed
Feb 26, 2025
Last updated
Oct 16, 2025
Summary
This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
Mitigation
Please update to 5.2.3 or later.
Workarounds
None
References
If you have any questions or comments about this advisory:
Email us at security@mautic.org
References