Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability.
https://github.com/mautic/mautic/security/advisories/GHSA-mgv8-w49f-822w