Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2021-27917

Disclosure Date: September 18, 2024 (last updated September 28, 2024)
Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
Attacker Value
Unknown

CVE-2021-27915

Disclosure Date: September 17, 2024 (last updated September 29, 2024)
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions. This could lead to the user having elevated access to the system.
Attacker Value
Unknown

CVE-2017-1000490

Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to.
0