In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Incorrect Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade mautic/core-lib
to version 5.2.3, 6.0.0-beta or higher.
Affected versions of this package are vulnerable to Incorrect Authorization via the Reporting API
. An attacker can gain unauthorized access to sensitive report data by exploiting the flawed HTTP Basic Authentication implementation.
Note:
This is only exploitable if the API is enabled and the user is authenticated, regardless of their assigned roles or permissions.