PT-2021-19299 · Mautic · Mautic

Published

2021-01-29

·

Updated

2021-01-29

·

CVE-2021-3142

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Mautic versions prior to 2.16.5 Mautic versions prior to 3.2.4
Description This issue relates to a cross-site scripting vulnerability that can be executed when creating or editing a company, requiring the user to be logged in as an administrator. The vulnerability was reported by Dardan Prebreza at Bishop Fox.
Recommendations Upgrade to version 2.16.5 or later for 2.x versions. Upgrade to version 3.2.4 or later for 3.x versions.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3142
GHSA-P7V4-GM6J-CW9M

Affected Products

Mautic