First published: Mon Jun 20 2022(Updated: )
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
Credit: security@mautic.org
Affected Software | Affected Version | How to fix |
---|---|---|
Acquia Mautic | <4.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this cross-site scripting (XSS) vulnerability is CVE-2022-25772.
The severity of CVE-2022-25772 is critical, with a severity value of 6.1.
The web tracking component of Mautic before version 4.3.0 is affected by CVE-2022-25772.
CVE-2022-25772 allows remote attackers to inject executable JavaScript through a cross-site scripting (XSS) vulnerability in the web tracking component of Mautic.
Yes, you can find references for CVE-2022-25772 at the following links: [link1](https://github.com/mautic/mautic/security/advisories/GHSA-pjpc-87mp-4332) and [link2](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00847.html).