
We found results for “”
CVE-2024-47058
Good to know:

Date: September 18, 2024
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.
Language: PHP
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version mautic/core - dev-dependabot/composer/composer/composer-2.6.4;mautic/core - dev-remove-mautibox-reference-4.1;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/async-3.2.3;mautic/core - dev-dependabot/composer/composer/composer-2.7.0;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/minimatch-3.1.2;mautic/core - dev-staging3.0.x-include-exclude-for-text-field;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/grunt-1.3.0;mautic/core - dev-dependabot/composer/composer/composer-2.7.7;mautic/core - dev-bump-4.4.3;mautic/core - dev-4.4.8-release;mautic/core - dev-all-contributors/add-code5rick;mautic/core - dev-dependabot/composer/twig/twig-3.3.8;mautic/core - dev-all-contributors/add-KN4CK3R;mautic/core - dev-3.2.2-merge;mautic/core - dev-update-security-policy-4.4;mautic/core - dev-RCheesley-patch-1;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/word-wrap-1.2.4;mautic/core - dev-bump-4.4.5;mautic/core - dev-fix-4-2-release;mautic/core - 4.4.13;mautic/core - dev-temp-2.16;mautic/core - 5.1.x-dev;mautic/core - dev-dependabot/composer/composer/composer-2.2.12;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/requirejs-2.3.7;mautic/core - dev-4.4.9-release;mautic/core - dev-RCheesley-patch-2;mautic/core - dev-merge-3.3.3-into-features;mautic/core - dev-bump-4.4.4;mautic/core - dev-dependabot/npm_and_yarn/braces-3.0.3;mautic/core - dev-bump-5.0.2;mautic/core - dev-temp-3.2;mautic/core - dev-dependabot/npm_and_yarn/micromatch-4.0.8;mautic/core - dev-bump-4.0.2-rc;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/ansi-regex-5.0.1;mautic/core - dev-dependabot/npm_and_yarn/app/assets/scaffold/files/grunt-1.5.2;mautic/core - dev-dependabot/npm_and_yarn/plugins/GrapesJsBuilderBundle/browserify-sign-4.2.2;mautic/core-lib - dev-4.4.8-release;mautic/core-lib - dev-4.4.9-release;mautic/core-lib - dev-dependabot/npm_and_yarn/assets/scaffold/files/braces-3.0.3;mautic/core-lib - 5.1.x-dev;mautic/core-lib - 4.4.13
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | HIGH |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | LOW |
Availability (A): | LOW |