Home
MEDIUM: 4.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NDefault status
unaffected
< 4.4.12
affected
Description
Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could inject malicious code into the notification when saving Dashboards.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
< 4.4.12
Credits
Vautia
Lenon Leite
Zdeno Kuzmany
John Linhart
References
github.com/...mautic/security/advisories/GHSA-fhcx-f7jg-jx3f