← Retour aux CVEs
CVE-2020-35128
CRITICAL9.0
Description
Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. These actions include changing the user passwords, altering user or email addresses, or adding a new administrator to the system.
Details CVE
Score CVSS v3.19.0
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurREQUIRED
Publie1/19/2021
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
acquia:mautic
Faiblesses (CWE)
CWE-79
References
https://forum.mautic.org/c/announcements/16(cve@mitre.org)
https://forum.mautic.org/t/security-release-for-all-versions-of-mautic-prior-to-2-16-5-and-3-2-4/17786(cve@mitre.org)
https://labs.bishopfox.com/advisories/mautic-version-3.2.2(cve@mitre.org)
https://forum.mautic.org/c/announcements/16(af854a3a-2127-422b-91ae-364da2661108)
https://forum.mautic.org/t/security-release-for-all-versions-of-mautic-prior-to-2-16-5-and-3-2-4/17786(af854a3a-2127-422b-91ae-364da2661108)
https://labs.bishopfox.com/advisories/mautic-version-3.2.2(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.