CVE-2017-8874: CSRF
Published May 10, 2017
·Updated
Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns or (2) delete contacts.
Affected Software
2 affected components
composer/mautic/core=1.4.1
Acquia Mautic=1.4.1
Event History
May 10, 2017
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
Description
May 13, 2022
Advisory Published
via GitHub·01:12 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-8874?
CVE-2017-8874 is classified as a medium severity vulnerability due to its ability to allow remote attackers to hijack user authentication.
2
How do I fix CVE-2017-8874?
To fix CVE-2017-8874, upgrade Mautic to version 1.4.2 or later where the vulnerabilities are addressed.
3
What attacks can CVE-2017-8874 be used for?
CVE-2017-8874 can be exploited for cross-site request forgery (CSRF) attacks that can delete email campaigns or contacts.
4
Is CVE-2017-8874 specific to any version of Mautic?
Yes, CVE-2017-8874 specifically affects Mautic version 1.4.1.
5
Can CVE-2017-8874 affect user data?
Yes, CVE-2017-8874 can lead to unauthorized deletion of user data, such as email campaigns and contacts.