CVE-2021-27915: XSS Cross-site Scripting Stored (XSS) - Description field
Impact Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions.
This could lead to the user having elevated access to the system.
Patches Update to 4.4.12
Workarounds None
References - https://owasp.org/www-project-top-ten/2017/A72017-Cross-SiteScripting(XSS) - https://owasp.org/www-project-web-security-testing-guide/latest/4-WebApplicationSecurityTesting/07-InputValidationTesting/02-TestingforStoredCrossSiteScripting
If you have any questions or comments about this advisory:
Email us at security@mautic.org
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27915?
CVE-2021-27915 has been classified as a medium severity vulnerability due to the potential for XSS attacks by logged-in users.
How do I fix CVE-2021-27915?
To fix CVE-2021-27915, update Mautic to version 4.4.12 or later.
Who is affected by CVE-2021-27915?
CVE-2021-27915 affects users of Mautic versions prior to 4.4.12, specifically those with permissions to modify description fields.
What type of vulnerability is CVE-2021-27915?
CVE-2021-27915 is an XSS (Cross-Site Scripting) vulnerability.
Can CVE-2021-27915 lead to escalation of privileges?
Yes, exploiting CVE-2021-27915 can potentially allow an attacker to gain elevated access within the Mautic application.