CVE-2021-27917: XSS in contact tracking and page hits report
Summary Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
Patches Please update to 4.4.13 or 5.1.1 or later.
Workarounds None
References https://owasp.org/www-project-top-ten/2017/A72017-Cross-SiteScripting(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-WebApplicationSecurityTesting/07-InputValidationTesting/02-TestingforStoredCrossSiteScripting
If you have any questions or comments about this advisory:
Email us at security@mautic.org
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27917?
CVE-2021-27917 is classified as a stored Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2021-27917?
To fix CVE-2021-27917, update your Mautic installation to version 4.4.13 or 5.1.1 or later.
What applications are affected by CVE-2021-27917?
CVE-2021-27917 affects Mautic versions prior to 4.4.13 and 5.1.1.
Is there a workaround for CVE-2021-27917?
There are currently no known workarounds for CVE-2021-27917, and applying the patch is recommended.
What types of attacks can exploit CVE-2021-27917?
CVE-2021-27917 can be exploited for stored XSS attacks, allowing malicious scripts to run in a user's browser.