icon

We found results for “

CVE-2024-47058

Good to know:

icon

Date: September 18, 2024

With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version mautic/core - dev-dependabot/composer/composer/composer-2.6.4;mautic/core - dev-remove-mautibox-reference-4.1;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/async-3.2.3;mautic/core - dev-dependabot/composer/composer/composer-2.7.0;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/minimatch-3.1.2;mautic/core - dev-staging3.0.x-include-exclude-for-text-field;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/grunt-1.3.0;mautic/core - dev-dependabot/composer/composer/composer-2.7.7;mautic/core - dev-bump-4.4.3;mautic/core - dev-4.4.8-release;mautic/core - dev-all-contributors/add-code5rick;mautic/core - dev-dependabot/composer/twig/twig-3.3.8;mautic/core - dev-all-contributors/add-KN4CK3R;mautic/core - dev-3.2.2-merge;mautic/core - dev-update-security-policy-4.4;mautic/core - dev-RCheesley-patch-1;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/word-wrap-1.2.4;mautic/core - dev-bump-4.4.5;mautic/core - dev-fix-4-2-release;mautic/core - 4.4.13;mautic/core - dev-temp-2.16;mautic/core - 5.1.x-dev;mautic/core - dev-dependabot/composer/composer/composer-2.2.12;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/requirejs-2.3.7;mautic/core - dev-4.4.9-release;mautic/core - dev-RCheesley-patch-2;mautic/core - dev-merge-3.3.3-into-features;mautic/core - dev-bump-4.4.4;mautic/core - dev-dependabot/npm_and_yarn/braces-3.0.3;mautic/core - dev-bump-5.0.2;mautic/core - dev-temp-3.2;mautic/core - dev-dependabot/npm_and_yarn/micromatch-4.0.8;mautic/core - dev-bump-4.0.2-rc;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/ansi-regex-5.0.1;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/grunt-1.5.2;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/browserify-sign-4.2.2;mautic/core-lib - dev-4.4.8-release;mautic/core-lib - dev-4.4.9-release;mautic/core-lib - dev-dependabot/npm_and_yarn/assets/scaffold/files/braces-3.0.3;mautic/core-lib - 5.1.x-dev;mautic/core-lib - 4.4.13

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): HIGH
Privileges Required (PR): HIGH
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us