CVE-2024-3448: Improper Access Control Leads to Server-Side Request Forgery in Mautic
Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeAvailability leads to a Server-Side Request Forgery by analyzing the error messages returned from the back-end. Allowing an attacker to perform a port scan in the back-end. At the time of publication of the CVE no patch is available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3448?
CVE-2024-3448 has been classified as a medium severity vulnerability.
What are the potential impacts of CVE-2024-3448?
CVE-2024-3448 can lead to a Server-Side Request Forgery (SSRF) by allowing low-privileged users to access sensitive AJAX actions.
Who is affected by CVE-2024-3448?
CVE-2024-3448 affects users of Mautic due to improper access controls on specific AJAX actions.
How do I fix CVE-2024-3448?
To fix CVE-2024-3448, ensure that proper access controls are implemented to prevent low-privileged users from accessing sensitive AJAX endpoints.
What versions of Mautic are impacted by CVE-2024-3448?
CVE-2024-3448 affects all versions of Mautic that have not implemented the necessary security controls.