← Retour aux CVEs
CVE-2020-35129
CRITICAL9.0
Description
Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally drafted JavaScript file that would allow them to eventually perform actions on the target user’s behalf, including changing the user’s password or email address or changing the attacker’s user role from a low-privileged user to an administrator account.
Details CVE
Score CVSS v3.19.0
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurREQUIRED
Publie1/19/2021
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
mautic:mautic
Faiblesses (CWE)
CWE-79
References
https://forum.mautic.org/c/announcements/16(cve@mitre.org)
https://labs.bishopfox.com/advisories/mautic-version-3.2.2(cve@mitre.org)
https://forum.mautic.org/c/announcements/16(af854a3a-2127-422b-91ae-364da2661108)
https://labs.bishopfox.com/advisories/mautic-version-3.2.2(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.