top of page
perceptive_background_267k.jpg

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the vali…

Published:

28 May 2026 at 22:00:00

Alert date:

29 May 2026 at 13:02:21

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A path traversal vulnerability in Mautic 7's campaign import feature allows authenticated users with campaign import privileges to write arbitrary PHP files to sensitive system directories. The flaw occurs during ZIP file extraction when validation logic fails to prevent file paths from escaping intended temporary directories. Attackers can exploit this to overwrite critical configuration or cache components, leading to Remote Code Execution under web server context. This requires authentication and specific campaign import permissions but results in full RCE capability.

Technical details

Mitigation steps:

Affected products:

Mautic 7

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page