Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| mautic/core(Packagist) | 1.0.0-beta4 | 4.4.12 | N/A |
| mautic/core(Packagist) | 5.0.0-alpha | 5.0.4 | N/A |
CVSS Metrics