PT-2024-10911 · Mautic · Mautic

Lenon Leite

+1

·

Published

2024-04-11

·

Updated

2024-09-29

·

CVE-2021-27915

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mautic versions prior to 4.4.12
Description There is an XSS vulnerability in the description fields within the Mautic application, which could be exploited by a logged-in user with the appropriate permissions. This could lead to the user having elevated access to the system.
Recommendations Update to version 4.4.12 to resolve the issue. As a temporary workaround, consider restricting access to the description fields within the Mautic application to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-27915
GHSA-2RC5-2755-V422

Affected Products

Mautic