CVE-2021-27912: XSS vulnerability on asset view
Impact Mautic versions before 3.3.4 / 4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets.
Patches Upgrade to 3.3.4 or 4.0.0
Workarounds No
References https://github.com/mautic/mautic/releases/tag/3.3.4 https://github.com/mautic/mautic/releases/tag/4.0.0
For more information If you have any questions or comments about this advisory: Email us at security@mautic.org
Other sources
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-27912?
CVE-2021-27912 is an XSS vulnerability that affects Mautic versions before 3.3.4/4.0.0.
How does CVE-2021-27912 work?
CVE-2021-27912 allows an authenticated user with permission to create or edit assets to execute an inline JS XSS attack by utilizing inline JS in the title and adding a broken image URL as a remote asset.
What is the severity of CVE-2021-27912?
The severity of CVE-2021-27912 is high with a CVSS score of 5.4.
Which software versions are affected by CVE-2021-27912?
Mautic versions before 3.3.4/4.0.0 are affected by CVE-2021-27912.
How can I fix CVE-2021-27912?
To fix CVE-2021-27912, you should update Mautic to version 3.3.4 or 4.0.0.