First published: Wed Jun 01 2022(Updated: )
A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascript
Credit: security@mautic.org
Affected Software | Affected Version | How to fix |
---|---|---|
Acquia Mautic | <4.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27914 is a cross-site scripting (XSS) vulnerability in the installer component of Mautic before version 4.3.0.
An admin can exploit CVE-2021-27914 by injecting executable JavaScript.
CVE-2021-27914 has a severity rating of high (4.8).
Mautic versions up to and excluding 4.3.0 are affected by CVE-2021-27914.
To fix CVE-2021-27914, upgrade to Mautic version 4.3.0 or newer.