PT-2024-10911 · Mautic · Mautic
Lenon Leite
+1
·
Published
2024-04-11
·
Updated
2024-09-29
·
CVE-2021-27915
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mautic versions prior to 4.4.12
Description
There is an XSS vulnerability in the description fields within the Mautic application, which could be exploited by a logged-in user with the appropriate permissions. This could lead to the user having elevated access to the system.
Recommendations
Update to version 4.4.12 to resolve the issue. As a temporary workaround, consider restricting access to the description fields within the Mautic application to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mautic