PT-2021-11713 · Mautic · Mautic
Dardan Prebreza
·
Published
2021-01-19
·
Updated
2022-05-24
·
CVE-2020-35129
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Mautic versions prior to 3.2.4
Description:
The issue affects Mautic, allowing an attacker with access to the Social Monitoring feature to perform stored XSS attacks on other users, including administrators. This could enable the attacker to load an externally drafted JavaScript file, potentially allowing them to change the target user's password or email address, or even elevate their own user role from a low-privileged user to an administrator account.
Recommendations:
For versions prior to 3.2.4, update to version 3.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Social Monitoring feature to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mautic