CVE-2022-25772: XSS
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this cross-site scripting (XSS) vulnerability?
The vulnerability ID for this cross-site scripting (XSS) vulnerability is CVE-2022-25772.
What is the severity of CVE-2022-25772?
The severity of CVE-2022-25772 is critical, with a severity value of 6.1.
What is affected by CVE-2022-25772?
The web tracking component of Mautic before version 4.3.0 is affected by CVE-2022-25772.
How does CVE-2022-25772 allow remote attackers to inject executable JavaScript?
CVE-2022-25772 allows remote attackers to inject executable JavaScript through a cross-site scripting (XSS) vulnerability in the web tracking component of Mautic.
Are there any references available for CVE-2022-25772?
Yes, you can find references for CVE-2022-25772 at the following links: [link1](https://github.com/mautic/mautic/security/advisories/GHSA-pjpc-87mp-4332) and [link2](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00847.html).