Description
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2108 | Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets. |
Github GHSA |
GHSA-rh5w-82wh-jhr8 | XSS vulnerability on asset view |
References
History
No history.
Status: PUBLISHED
Assigner: Mautic
Published:
Updated: 2024-09-16T16:17:39.112Z
Reserved: 2021-03-02T00:00:00.000Z
Link: CVE-2021-27912
No data.
Status : Modified
Published: 2021-08-30T16:15:07.403
Modified: 2024-11-21T05:58:47.070
Link: CVE-2021-27912
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA