PT-2018-9742 · Mautic · Mautic

Micschk

·

Published

2018-04-17

·

Updated

2021-01-19

·

CVE-2018-10189

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mautic versions 1.x and 2.x before 2.13.0
Description: An issue was discovered in Mautic where it is possible to systematically emulate tracking cookies per contact due to tracking the contact by their auto-incremented ID. A third party can manipulate the cookie value with +1 to systematically assume being tracked as each contact in Mautic. It is then possible to retrieve information about the contact through forms that have progressive profiling enabled.
Recommendations: Update to 2.13.0 or later. As a temporary workaround, consider restricting access to forms with progressive profiling enabled until the update is applied.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10189
GHSA-VFXJ-QG93-7WWC

Affected Products

Mautic