Опубликовано: 18 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 4.8
Описание
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Impact
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.
Patches
Upgrade to 4.4.13 or 5.1.1 or later.
Workarounds
None
References
- https://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS)
- https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/02-Testing_for_Stored_Cross_Site_Scripting
If you have any questions or comments about this advisory:
Email us at security@mautic.org
Пакеты
Наименование
mautic/core
composer
Затронутые версииВерсия исправления
>= 5.0.0-alpha, < 5.1.1
5.1.1
Наименование
mautic/core
composer
Затронутые версииВерсия исправления
>= 1.0.0-beta, < 4.4.13
4.4.13
Наименование
mautic/core-lib
composer
Затронутые версииВерсия исправления
>= 5.0.0-alpha, < 5.1.1
5.1.1
Наименование
mautic/core-lib
composer
Затронутые версииВерсия исправления
>= 1.0.0-beta, < 4.4.13
4.4.13
Связанные уязвимости
CVSS3: 2.9
nvd
больше 1 года назад
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.