← Voltar para CVEs
CVE-2020-35129
CRITICAL9.0
Descricao
Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally drafted JavaScript file that would allow them to eventually perform actions on the target user’s behalf, including changing the user’s password or email address or changing the attacker’s user role from a low-privileged user to an administrator account.
Detalhes CVE
Pontuacao CVSS v3.19.0
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioREQUIRED
Publicado1/19/2021
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
mautic:mautic
Fraquezas (CWE)
CWE-79
Referencias
https://forum.mautic.org/c/announcements/16(cve@mitre.org)
https://labs.bishopfox.com/advisories/mautic-version-3.2.2(cve@mitre.org)
https://forum.mautic.org/c/announcements/16(af854a3a-2127-422b-91ae-364da2661108)
https://labs.bishopfox.com/advisories/mautic-version-3.2.2(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.