Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-98j2-3jv7-274m

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9

Описание

Mautic stored Cross-site Scripting (XSS)

Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. These actions include changing the user passwords, altering user or email addresses, or adding a new administrator to the system.

Пакеты

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 3.2.0, < 3.2.4

3.2.4

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.16.5

2.16.5

EPSS

Процентиль: 70%
0.00651
Низкий

9 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9
nvd
около 5 лет назад

Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. These actions include changing the user passwords, altering user or email addresses, or adding a new administrator to the system.

EPSS

Процентиль: 70%
0.00651
Низкий

9 Critical

CVSS3

Дефекты

CWE-79