
We found results for “”
CVE-2020-35124
Good to know:

Date: January 28, 2021
A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.
Language: PHP
Severity Score
Related Resources (9)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version mautic/core - dev-fix-ddev;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/requirejs-2.3.7;mautic/core - 3.2.3;mautic/core - dev-fix-company-datetime-empty-segment-filter;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/grunt-1.5.2;mautic/core - dev-temp-3.2;mautic/core - 2.16.5;mautic/core - dev-dependabot/npm_and_yarn/braces-3.0.3;mautic/core - dev-RCheesley-patch-1;mautic/core - dev-temp-2.16;mautic/core - dev-dependabot/composer/composer/composer-2.7.0;mautic/core - dev-staging3.0.x-include-exclude-for-text-field;mautic/core - dev-add-allow-redirect-in-download-request;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/word-wrap-1.2.4;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/minimatch-3.1.2;mautic/core - dev-RCheesley-patch-2;mautic/core - dev-all-contributors/add-Christophe9880;mautic/core - dev-stop-duplicate-campaign-update;mautic/core - dev-dependabot/composer/composer/composer-2.6.4;mautic/core - dev-dependabot/composer/composer/composer-2.2.12;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/grunt-1.3.0;mautic/core - dev-dependabot/composer/composer/composer-2.7.7;friendsofmautic/bundle-skeleton - 1.3.0
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |