CVE-2024-47051 describes two critical vulnerabilities affecting Mautic versions prior to 5.2.3: a Remote Code Execution (RCE) flaw in asset upload and a Path Traversal vulnerability allowing arbitrary file deletion. With a CVSS score of 9.9 (CRITICAL), these issues can be exploited by authenticated users over the network with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While no active exploitation or public exploit code is currently reported, and community discussion is minimal, the high FAUCET Risk Score of 89/100 indicates significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.3CPE matchmatch criteria | cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.