Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p7v4-gm6j-cw9m

Опубликовано: 29 янв. 2021
Источник: github
Github: Прошло ревью

Описание

XSS in Mautic

Impact

This is a cross-site scripting vulnerability relating to creating/editing a company which requires the user to be logged in as an administrator to be executed.

This vulnerability was reported by Dardan Prebreza at Bishop Fox.

Patches

Upgrade to 3.2.4 or 2.16.5.

Link to patch for 2.x versions: https://github.com/mautic/mautic/compare/2.16.4...2.16.5.diff

Link to patch for 3.x versions: https://github.com/mautic/mautic/compare/3.2.2...3.2.4.diff

Workarounds

None

References

https://www.mautic.org/blog/community/security-release-all-versions-mautic-prior-2-16-5-and-3-2-4

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 3.0.0, < 3.2.4

3.2.4

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.16.5

2.16.5

Дефекты

CWE-79

Связанные уязвимости

nvd
около 5 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35128. Reason: This candidate is a reservation duplicate of CVE-2020-35128. Notes: All CVE users should reference CVE-2020-35128 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

Дефекты

CWE-79