github.com
https://github.com/mautic/mautic CVE-2021-27917
XSS in contact tracking and page hits report
Description
Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 19, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | >= 1.0.0-beta4 to < < 4.4.13 | affected |
| >= 5.0.0 to < < 5.1.1 | affected | ||
mautic/coreBrowse Packagist / mautic/core | GitHub Advisory | 1.0.0-beta4 to < 4.4.13 · Fixed in 4.4.13 | affected |
| 5.0.0-alpha to < 5.1.1 · Fixed in 5.1.1 | affected | ||
mautic/core-libBrowse Packagist / mautic/core-lib | GitHub Advisory | 1.0.0-beta4 to < 4.4.13 · Fixed in 4.4.13 | affected |
| 5.0.0-alpha to < 5.1.1 · Fixed in 5.1.1 | affected |
References
5github.com
https://github.com/mautic/mautic/commit/550e33562d03363f7592fa9354259787a23a1d98 github.com
https://github.com/mautic/mautic/commit/629165ac905c53bbb44feb5a6dbadb1dfd6d5564 github.com
https://github.com/mautic/mautic/security/advisories/GHSA-xpc5-rr39-v8v2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-27917