Show filters
29 Total Results
Displaying 1-10 of 29
Sort by:
Attacker Value
Unknown
CVE-2021-27917
Disclosure Date: September 18, 2024 (last updated September 28, 2024)
Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
0
Attacker Value
Unknown
CVE-2024-47058
Disclosure Date: September 18, 2024 (last updated September 28, 2024)
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.
0
Attacker Value
Unknown
CVE-2024-47050
Disclosure Date: September 18, 2024 (last updated September 28, 2024)
Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable.
0
Attacker Value
Unknown
CVE-2022-25776
Disclosure Date: September 18, 2024 (last updated September 25, 2024)
Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing.
Users could potentially access sensitive data such as names and surnames, company names and stage names.
0
Attacker Value
Unknown
CVE-2022-25775
Disclosure Date: September 18, 2024 (last updated September 24, 2024)
Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle.
The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.
0
Attacker Value
Unknown
CVE-2022-25774
Disclosure Date: September 18, 2024 (last updated September 24, 2024)
Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic.
Users could inject malicious code into the notification when saving Dashboards.
0
Attacker Value
Unknown
CVE-2021-27916
Disclosure Date: September 17, 2024 (last updated October 03, 2024)
Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete files other than those in the media folders such as system files, libraries or other important files.
This vulnerability exists in the implementation of the GrapesJS builder in Mautic.
0
Attacker Value
Unknown
CVE-2021-27915
Disclosure Date: September 17, 2024 (last updated September 29, 2024)
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions.
This could lead to the user having elevated access to the system.
0
Attacker Value
Unknown
CVE-2022-25772
Disclosure Date: June 20, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
0
Attacker Value
Unknown
CVE-2021-27914
Disclosure Date: June 01, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascript
0