PT-2021-11711 · Mautic · Mautic

Naveen Sunkavally

·

Published

2021-02-09

·

Updated

2024-05-15

·

CVE-2020-35125

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Mautic versions prior to 2.16.5 Mautic versions prior to 3.2.4
Description: A cross-site scripting (XSS) issue in the forms component allows remote attackers to inject executable JavaScript via mautic[return]. This could allow an attacker unauthorized administrator-level access to Mautic. The vulnerability was reported by Naveen Sunkavally at Horizon3.ai.
Recommendations: For versions prior to 2.16.5, upgrade to 2.16.5. For versions prior to 3.2.4, upgrade to 3.2.4. As a temporary workaround, consider restricting access to the forms component until a patch is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-35125
GHSA-42Q7-95J7-W62M

Affected Products

Mautic