Mautic stored Cross-site Scripting (XSS)
Critical severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated May 3, 2024
Description
Published by the National Vulnerability Database
Jan 19, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Apr 23, 2024
Last updated
May 3, 2024
Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally drafted JavaScript file that would allow them to eventually perform actions on the target user’s behalf, including changing the user’s password or email address or changing the attacker’s user role from a low-privileged user to an administrator account.
References