PT-2021-17666 · Mautic · Mautic

Rcheesley

·

Published

2021-08-30

·

Updated

2021-09-03

·

CVE-2021-27912

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Mautic versions prior to 3.3.4 Mautic versions prior to 4.0.0
Description: The issue allows for an inline JS XSS attack when viewing Mautic assets. This is achieved by utilizing inline JS in the title and adding a broken image URL as a remote asset. The attack can only be leveraged by an authenticated user with permission to create or edit assets.
Recommendations: Upgrade to version 3.3.4 or 4.0.0 to resolve the issue. As a temporary workaround, consider restricting access to create or edit assets to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27912
GHSA-RH5W-82WH-JHR8

Affected Products

Mautic