Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rh5w-82wh-jhr8

Опубликовано: 01 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

XSS vulnerability on asset view

Impact

Mautic versions before 3.3.4 / 4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets.

Patches

Upgrade to 3.3.4 or 4.0.0

Workarounds

No

References

https://github.com/mautic/mautic/releases/tag/3.3.4 https://github.com/mautic/mautic/releases/tag/4.0.0

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

< 3.3.4

3.3.4

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 4.0.0-alpha1, < 4.0.0

4.0.0

EPSS

Процентиль: 67%
0.00527
Низкий

7.1 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.1
nvd
больше 4 лет назад

Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets.

EPSS

Процентиль: 67%
0.00527
Низкий

7.1 High

CVSS3

Дефекты

CWE-79