{"id":"GHSA-hj6f-7hp7-xg69","summary":"Mautic vulnerable to SSRF via webhook function","details":"### Summary\nUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed\n\n### Details\nWhen sending webhooks, the destination is not validated, causing SSRF.\n\n### Impact\nBypass of firewalls to interact with internal services. \nSee https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact.\n\n### Resources\nhttps://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix","aliases":["CVE-2025-9821"],"modified":"2025-09-03T22:27:22.395120Z","published":"2025-09-03T22:11:32Z","database_specific":{"github_reviewed_at":"2025-09-03T22:11:32Z","nvd_published_at":"2025-09-03T10:15:38Z","cwe_ids":["CWE-918"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/mautic/mautic/security/advisories/GHSA-hj6f-7hp7-xg69"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9821"},{"type":"WEB","url":"https://github.com/mautic/mautic/commit/6084f6de4c88d1aeb5f6c73ea4fe1b09c98ea52b"},{"type":"WEB","url":"https://github.com/mautic/mautic/commit/dc5bb1466c9a48fd34768dc8ff5888716b2916ba"},{"type":"PACKAGE","url":"https://github.com/mautic/mautic"}],"affected":[{"package":{"name":"mautic/core","ecosystem":"Packagist","purl":"pkg:composer/mautic/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.4.0"},{"fixed":"4.4.17"}]}],"versions":["4.4.0","4.4.1","4.4.10","4.4.11","4.4.12","4.4.13","4.4.2","4.4.3","4.4.4","4.4.5","4.4.6","4.4.7","4.4.8","4.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-hj6f-7hp7-xg69/GHSA-hj6f-7hp7-xg69.json"}},{"package":{"name":"mautic/core","ecosystem":"Packagist","purl":"pkg:composer/mautic/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0-alpha"},{"fixed":"5.2.8"}]}],"versions":["5.0.0","5.0.0-alpha","5.0.0-alpha1","5.0.0-beta1","5.0.0-beta2","5.0.0-rc1","5.0.0-rc2","5.0.1","5.0.2","5.0.3","5.0.4","5.1.0","5.1.1","5.2.0","5.2.1","5.2.2","5.2.3","5.2.4","5.2.5","5.2.6","5.2.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-hj6f-7hp7-xg69/GHSA-hj6f-7hp7-xg69.json"}},{"package":{"name":"mautic/core","ecosystem":"Packagist","purl":"pkg:composer/mautic/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0-alpha"},{"fixed":"6.0.5"}]}],"versions":["6.0.0","6.0.0-alpha","6.0.0-beta2","6.0.0-rc","6.0.1","6.0.2","6.0.3","6.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-hj6f-7hp7-xg69/GHSA-hj6f-7hp7-xg69.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"}]}