PT-2026-44823 · Mautic · Mautic
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Mautic versions prior to 7.1.2
Description
A stored Cross-Site Scripting (XSS) issue exists in the project selector component. The application fails to sanitize project names returned via AJAX before injecting them into the Document Object Model (DOM) as option fields. An authenticated user with project creation permissions can store a malicious script payload in a project name. When an administrative user opens an entity editor containing the project selector, the script executes in their browser session, potentially leading to session hijacking, unauthorized state coordination, or unauthorized access to organizational data.
Recommendations
Update to version 7.1.2.
Restrict project creation and modification permissions to trusted administrative users.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mautic