Vulnerability Description
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Acquia | Mautic | < 3.3.4 |
Related Weaknesses (CWE)
References
- https://github.com/mautic/mautic/security/advisories/GHSA-rh5w-82wh-jhr8PatchThird Party Advisory
- https://github.com/mautic/mautic/security/advisories/GHSA-rh5w-82wh-jhr8PatchThird Party Advisory
FAQ
What is CVE-2021-27912?
CVE-2021-27912 is a vulnerability with a CVSS score of 7.1 (HIGH). Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can on...
How severe is CVE-2021-27912?
CVE-2021-27912 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27912?
Check the references section above for vendor advisories and patch information. Affected products include: Acquia Mautic.