First published: Fri Sep 06 2019(Updated: )
### Impact An XSS vulnerability was discovered in Mautic 2.13.1 in the Author URL of themes. ### Patches Update to 2.14 or later ### Workarounds None ### References https://github.com/mautic/mautic/releases/tag/2.14.0 ### For more information If you have any questions or comments about this advisory: * Email us at [security@mautic.org](mailto:security@mautic.org)
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/mautic/core | =2.13.1 | 2.14.0 |
Acquia Mautic | =2.13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-11198.
The impact of this vulnerability is a Stored XSS (Cross-Site Scripting) via the authorUrl field in config.json in Mautic 2.13.1.
CVE-2018-11198 has a severity rating of 6.1, which is considered medium severity.
To fix CVE-2018-11198, it is recommended to update Mautic to version 2.14 or later.
There are no known workarounds for CVE-2018-11198.