CVE-2021-27912
XSS vulnerability on asset view
Severity Score
5.4
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets.
Mautic versiones anteriores a 3.3.4/4.0.0, son vulnerables a un ataque de tipo JS XSS en línea cuando se visualizan activos de Mautic al usar JS en línea en el título y añadiendo una URL de imagen rota como activo remoto. Esto sólo puede ser aprovechado por un usuario autenticado con permiso para crear o editar activos.
*Credits:
Reported by Hoang Nguyen https://github.com/MatisAct, Fixed by Rohit Pavaskar https://github.com/rohitp19
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-03-02 CVE Reserved
- 2021-08-30 CVE Published
- 2023-03-23 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/mautic/mautic/security/advisories/GHSA-rh5w-82wh-jhr8 | 2021-09-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Acquia Search vendor "Acquia" | Mautic Search vendor "Acquia" for product "Mautic" | < 3.3.4 Search vendor "Acquia" for product "Mautic" and version " < 3.3.4" | - |
Affected
| ||||||
Acquia Search vendor "Acquia" | Mautic Search vendor "Acquia" for product "Mautic" | 4.0.0 Search vendor "Acquia" for product "Mautic" and version "4.0.0" | alpha1 |
Affected
| ||||||
Acquia Search vendor "Acquia" | Mautic Search vendor "Acquia" for product "Mautic" | 4.0.0 Search vendor "Acquia" for product "Mautic" and version "4.0.0" | beta |
Affected
| ||||||
Acquia Search vendor "Acquia" | Mautic Search vendor "Acquia" for product "Mautic" | 4.0.0 Search vendor "Acquia" for product "Mautic" and version "4.0.0" | rc |
Affected
|