
We found results for “”
CVE-2020-35128
Good to know:

Date: January 19, 2021
Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. These actions include changing the user passwords, altering user or email addresses, or adding a new administrator to the system.
Language: PHP
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/grunt-1.5.2;mautic/core - dev-dependabot/composer/composer/composer-2.2.12;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/word-wrap-1.2.4;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/async-3.2.3;mautic/core - dev-RCheesley-patch-2;mautic/core - dev-dependabot/composer/composer/composer-2.6.4;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/requirejs-2.3.7;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/minimatch-3.1.2;mautic/core - dev-staging3.0.x-include-exclude-for-text-field;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/grunt-1.3.0;mautic/core - dev-dependabot/composer/composer/composer-2.7.7;mautic/core - dev-dependabot/npm_and_yarn/braces-3.0.3;mautic/core - dev-3.2.2-merge;mautic/core - dev-dependabot/composer/composer/composer-2.7.0;mautic/core - dev-temp-2.16;mautic/core - dev-RCheesley-patch-1;mautic/core - dev-temp-3.2
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | SINGLE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |