Skip to content

XSS Cross-site Scripting Stored (XSS) - Description field

High
RCheesley published GHSA-2rc5-2755-v422 Apr 11, 2024

Package

composer mautic/core (Composer)

Affected versions

>= 1.0.0-beta2

Patched versions

4.4.12

Description

Impact

Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions.

This could lead to the user having elevated access to the system.

Patches

Update to 4.4.12

Workarounds

None

References

If you have any questions or comments about this advisory:

Email us at security@mautic.org

Severity

High
7.6
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

CVE ID

CVE-2021-27915

Weaknesses