Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhcx-f7jg-jx3f

Опубликовано: 12 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

Mautic vulnerable to cross-site scripting in notifications via saving Dashboards

Impact

Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic.

Users could inject malicious code into the notification when saving Dashboards.

Patches

Update to Mautic 4.4.12.

Workarounds

None

References

If you have any questions or comments about this advisory:

Email us at security@mautic.org

Пакеты

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

< 4.4.12

4.4.12

EPSS

Процентиль: 17%
0.00055
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79
CWE-80

Связанные уязвимости

CVSS3: 4.8
nvd
больше 1 года назад

Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could inject malicious code into the notification when saving Dashboards.

EPSS

Процентиль: 17%
0.00055
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79
CWE-80