Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-27915


Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions. This could lead to the user having elevated access to the system.


Published

2024-09-17T14:15:14.100

Last Modified

2024-09-29T00:22:31.787

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.6 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-80
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application acquia mautic < 4.4.12 Yes
Application acquia mautic 1.0.0 Yes
Application acquia mautic 1.0.0 Yes
Application acquia mautic 1.0.0 Yes
Application acquia mautic 1.0.0 Yes
Application acquia mautic 1.0.0 Yes
Application acquia mautic 1.0.0 Yes
Application acquia mautic 1.0.0 Yes
Application acquia mautic 1.0.0 Yes

References