Описание
XSS vulnerability in Author URL of themes in Mautic
Impact
An XSS vulnerability was discovered in Mautic 2.13.1 in the Author URL of themes.
Patches
Update to 2.14 or later
Workarounds
None
References
https://github.com/mautic/mautic/releases/tag/2.14.0
For more information
If you have any questions or comments about this advisory:
- Email us at security@mautic.org
Пакеты
Наименование
mautic/core
composer
Затронутые версииВерсия исправления
= 2.13.1
2.14.0
Связанные уязвимости
CVSS3: 6.1
nvd
больше 6 лет назад
An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.