PT-2021-17666 · Mautic · Mautic
Rcheesley
·
Published
2021-08-30
·
Updated
2021-09-03
·
CVE-2021-27912
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Mautic versions prior to 3.3.4
Mautic versions prior to 4.0.0
Description:
The issue allows for an inline JS XSS attack when viewing Mautic assets. This is achieved by utilizing inline JS in the title and adding a broken image URL as a remote asset. The attack can only be leveraged by an authenticated user with permission to create or edit assets.
Recommendations:
Upgrade to version 3.3.4 or 4.0.0 to resolve the issue.
As a temporary workaround, consider restricting access to create or edit assets to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mautic