First published: Mon Aug 30 2021(Updated: )
### Impact Mautic versions before 3.3.4 / 4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets. ### Patches Upgrade to 3.3.4 or 4.0.0 ### Workarounds No ### References https://github.com/mautic/mautic/releases/tag/3.3.4 https://github.com/mautic/mautic/releases/tag/4.0.0 ### For more information If you have any questions or comments about this advisory: * Email us at [security@mautic.org](mailto:security@mautic.org)
Credit: security@mautic.org security@mautic.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/mautic/core | <4.0.0>=3.3.0<3.3.4>=3.2.0<3.3.0>=3.1.0<3.2.0>=3.0.0<3.1.0 | |
Acquia Mautic | <3.3.4 | |
Acquia Mautic | =4.0.0-alpha1 | |
Acquia Mautic | =4.0.0-beta | |
Acquia Mautic | =4.0.0-rc | |
composer/mautic/core | >=4.0.0-alpha1<4.0.0 | 4.0.0 |
composer/mautic/core | <3.3.4 | 3.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27912 is an XSS vulnerability that affects Mautic versions before 3.3.4/4.0.0.
CVE-2021-27912 allows an authenticated user with permission to create or edit assets to execute an inline JS XSS attack by utilizing inline JS in the title and adding a broken image URL as a remote asset.
The severity of CVE-2021-27912 is high with a CVSS score of 5.4.
Mautic versions before 3.3.4/4.0.0 are affected by CVE-2021-27912.
To fix CVE-2021-27912, you should update Mautic to version 3.3.4 or 4.0.0.