CVE-2024-47050: XSS in contact/company tracking (no authentication)
Summary Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable. Patches Please update to 4.4.13 or 5.1.1 or later.
Workarounds None
References https://owasp.org/www-project-top-ten/2017/A72017-Cross-SiteScripting(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-WebApplicationSecurityTesting/07-InputValidationTesting/02-TestingforStoredCrossSiteScripting
If you have any questions or comments about this advisory: Email us at security@mautic.org
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47050?
CVE-2024-47050 is classified as a Cross-Site Scripting (XSS) vulnerability that can lead to potential data compromise.
How do I fix CVE-2024-47050?
To fix CVE-2024-47050, update Mautic to version 4.4.13 or 5.1.1 or later.
What software is affected by CVE-2024-47050?
CVE-2024-47050 affects Mautic versions prior to 4.4.13 and 5.1.1.
Are there any workarounds for CVE-2024-47050?
There are no known workarounds for CVE-2024-47050, so updating is essential.
What type of vulnerability is CVE-2024-47050?
CVE-2024-47050 is a Cross-Site Scripting (XSS) vulnerability impacting Mautic's tracking functionality.