CVE-2021-27914: XSS
Published Jun 1, 2022
·Updated
A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascript
Affected Software
1 affected component
Acquia Mautic<4.3.0
Event History
Jun 1, 2022
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-27914?
CVE-2021-27914 is a cross-site scripting (XSS) vulnerability in the installer component of Mautic before version 4.3.0.
2
How can an admin exploit CVE-2021-27914?
An admin can exploit CVE-2021-27914 by injecting executable JavaScript.
3
What is the severity of CVE-2021-27914?
CVE-2021-27914 has a severity rating of high (4.8).
4
Which software versions are affected by CVE-2021-27914?
Mautic versions up to and excluding 4.3.0 are affected by CVE-2021-27914.
5
How can I fix CVE-2021-27914?
To fix CVE-2021-27914, upgrade to Mautic version 4.3.0 or newer.