// For flags

CVE-2020-35128

 

Severity Score

9.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. These actions include changing the user passwords, altering user or email addresses, or adding a new administrator to the system.

Mautic versiones anteriores a 3.2.4, está afectado por una vulnerabilidad de tipo XSS almacenado. Un atacante con permiso para administrar empresas, una funcionalidad de la aplicación, podría atacar a otros usuarios, incluyendo los administradores. Por ejemplo, al cargar un archivo JavaScript diseñado externamente, un atacante podría eventualmente llevar a cabo acciones como el usuario objetivo. Estas acciones incluyen cambiar las contraseñas de los usuarios, alterar las direcciones de correo electrónico o de usuario o agregar un nuevo administrador al sistema

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-11 CVE Reserved
  • 2021-01-19 CVE Published
  • 2024-05-24 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Acquia
Search vendor "Acquia"
Mautic
Search vendor "Acquia" for product "Mautic"
>= 2.0.0 < 2.16.5
Search vendor "Acquia" for product "Mautic" and version " >= 2.0.0 < 2.16.5"
-
Affected
Acquia
Search vendor "Acquia"
Mautic
Search vendor "Acquia" for product "Mautic"
>= 3.2.0 < 3.2.4
Search vendor "Acquia" for product "Mautic" and version " >= 3.2.0 < 3.2.4"
-
Affected