Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-2108 Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets.
Github GHSA Github GHSA GHSA-rh5w-82wh-jhr8 XSS vulnerability on asset view
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mautic

Published:

Updated: 2024-09-16T16:17:39.112Z

Reserved: 2021-03-02T00:00:00

Link: CVE-2021-27912

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-30T16:15:07.403

Modified: 2024-11-21T05:58:47.070

Link: CVE-2021-27912

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses