CVE-2017-1000490: Acquia Mautic

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to.

Affected products

  • Acquia Mautic: version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only; version 1.1.0 only; …
  • Mautic Mautic: version 1.0.0 only; version 1.2.0 only; version 2.9.0 only; version 2.9.2 only; version 2.10.0 only; version 2.11.0 only

Published 2018-01-03. Last modified 2026-06-17.