PT-2021-11713 · Mautic · Mautic

Dardan Prebreza

·

Published

2021-01-19

·

Updated

2022-05-24

·

CVE-2020-35129

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Mautic versions prior to 3.2.4
Description: The issue affects Mautic, allowing an attacker with access to the Social Monitoring feature to perform stored XSS attacks on other users, including administrators. This could enable the attacker to load an externally drafted JavaScript file, potentially allowing them to change the target user's password or email address, or even elevate their own user role from a low-privileged user to an administrator account.
Recommendations: For versions prior to 3.2.4, update to version 3.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Social Monitoring feature to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35129
GHSA-3PX5-WJH3-9X6R

Affected Products

Mautic