PT-2021-11710 · Mautic · Mautic
Naveen Sunkavally
·
Published
2021-01-19
·
Updated
2021-02-09
·
CVE-2020-35124
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Mautic versions prior to 2.16.5
Mautic versions prior to 3.2.4
Description:
A cross-site scripting (XSS) issue in the assets component allows remote attackers to inject executable JavaScript through the Referer header of asset downloads. This could allow an attacker unauthorized administrator-level access to Mautic.
Recommendations:
For versions prior to 2.16.5, upgrade to 2.16.5.
For versions prior to 3.2.4, upgrade to 3.2.4.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mautic