Lucene search

K
cveMitreCVE-2017-1000490
HistoryJan 03, 2018 - 5:29 p.m.

CVE-2017-1000490

2018-01-0317:29:00
CWE-22
mitre
web.nvd.nist.gov
47
mautic
filemanager
server vulnerability
cve-2017-1000490
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

26.3%

Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to.

Affected configurations

Nvd
Node
acquiamauticMatch1.0.1
OR
acquiamauticMatch1.0.2
OR
acquiamauticMatch1.0.3
OR
acquiamauticMatch1.0.4
OR
acquiamauticMatch1.0.5
OR
acquiamauticMatch1.1.0
OR
acquiamauticMatch1.1.1
OR
acquiamauticMatch1.1.2
OR
acquiamauticMatch1.1.3
OR
acquiamauticMatch1.2.0beta1
OR
acquiamauticMatch1.2.1
OR
acquiamauticMatch1.2.2
OR
acquiamauticMatch1.2.3
OR
acquiamauticMatch1.2.4
OR
acquiamauticMatch1.3.0
OR
acquiamauticMatch1.3.1
OR
acquiamauticMatch1.4.0
OR
acquiamauticMatch1.4.1
OR
acquiamauticMatch2.0.0
OR
acquiamauticMatch2.0.1
OR
acquiamauticMatch2.1.0
OR
acquiamauticMatch2.1.1
OR
acquiamauticMatch2.2.0
OR
acquiamauticMatch2.2.1
OR
acquiamauticMatch2.3.0
OR
acquiamauticMatch2.4.0
OR
acquiamauticMatch2.5.0
OR
acquiamauticMatch2.5.1
OR
acquiamauticMatch2.6.0
OR
acquiamauticMatch2.6.1
OR
acquiamauticMatch2.7.0
OR
acquiamauticMatch2.7.1
OR
acquiamauticMatch2.8.0
OR
acquiamauticMatch2.8.1
OR
acquiamauticMatch2.8.2
OR
acquiamauticMatch2.9.0beta
OR
acquiamauticMatch2.9.1
OR
acquiamauticMatch2.10.0beta
OR
acquiamauticMatch2.10.1
OR
acquiamauticMatch2.11.0beta
OR
mauticmauticMatch1.0.0
OR
mauticmauticMatch1.2.0
OR
mauticmauticMatch2.9.0
OR
mauticmauticMatch2.9.2
OR
mauticmauticMatch2.10.0
OR
mauticmauticMatch2.11.0
VendorProductVersionCPE
acquiamautic1.0.1cpe:2.3:a:acquia:mautic:1.0.1:*:*:*:*:*:*:*
acquiamautic1.0.2cpe:2.3:a:acquia:mautic:1.0.2:*:*:*:*:*:*:*
acquiamautic1.0.3cpe:2.3:a:acquia:mautic:1.0.3:*:*:*:*:*:*:*
acquiamautic1.0.4cpe:2.3:a:acquia:mautic:1.0.4:*:*:*:*:*:*:*
acquiamautic1.0.5cpe:2.3:a:acquia:mautic:1.0.5:*:*:*:*:*:*:*
acquiamautic1.1.0cpe:2.3:a:acquia:mautic:1.1.0:*:*:*:*:*:*:*
acquiamautic1.1.1cpe:2.3:a:acquia:mautic:1.1.1:*:*:*:*:*:*:*
acquiamautic1.1.2cpe:2.3:a:acquia:mautic:1.1.2:*:*:*:*:*:*:*
acquiamautic1.1.3cpe:2.3:a:acquia:mautic:1.1.3:*:*:*:*:*:*:*
acquiamautic1.2.0cpe:2.3:a:acquia:mautic:1.2.0:beta1:*:*:*:*:*:*
Rows per page:
1-10 of 461

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

26.3%

Related for CVE-2017-1000490