CVE-2025-5257
Predictable Page Indexing Might Lead to Sensitive Data Exposure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., /page/preview/1, /page/preview/2), lacked proper authorization checks. This allowed any unauthenticated user to view content that was not yet intended for public release, and allowed search engines to index these private preview URLs, making the content publicly discoverable.
MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later.
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. Unauthorized Access to Unpublished Page Previews: The page preview functionality for unpublished content, accessible via predictable URLs (e.g., /page/preview/1, /page/preview/2), lacked proper authorization checks. This allowed any unauthenticated user to view content that was not yet intended for public release, and allowed search engines to index these private preview URLs, making the content publicly discoverable. MitigationMautic has patched this vulnerability by enforcing proper permission checks on preview pages. Users should upgrade to the patched version of Mautic or later.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2025-05-27 CVE Reserved
- 2025-05-28 CVE Published
- 2025-05-28 CVE Updated
- 2025-05-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1284: Improper Validation of Specified Quantity in Input
CAPEC
- CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mautic Search vendor "Mautic" | Mautic Search vendor "Mautic" for product "Mautic" | < 6.0.2 Search vendor "Mautic" for product "Mautic" and version " < 6.0.2" | en |
Affected
| ||||||
Mautic Search vendor "Mautic" | Mautic Search vendor "Mautic" for product "Mautic" | < 5.4.6 Search vendor "Mautic" for product "Mautic" and version " < 5.4.6" | en |
Affected
| ||||||
Mautic Search vendor "Mautic" | Mautic Search vendor "Mautic" for product "Mautic" | < 4.4.16 Search vendor "Mautic" for product "Mautic" and version " < 4.4.16" | en |
Affected
|