CVE-2018-11198: XSS
Impact An XSS vulnerability was discovered in Mautic 2.13.1 in the Author URL of themes.
Patches Update to 2.14 or later
Workarounds None
References https://github.com/mautic/mautic/releases/tag/2.14.0
For more information If you have any questions or comments about this advisory: Email us at security@mautic.org
Other sources
An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-11198.
What is the impact of this vulnerability?
The impact of this vulnerability is a Stored XSS (Cross-Site Scripting) via the authorUrl field in config.json in Mautic 2.13.1.
How severe is CVE-2018-11198?
CVE-2018-11198 has a severity rating of 6.1, which is considered medium severity.
How do I fix CVE-2018-11198?
To fix CVE-2018-11198, it is recommended to update Mautic to version 2.14 or later.
Are there any workarounds for CVE-2018-11198?
There are no known workarounds for CVE-2018-11198.