Impact Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions.
This could lead to the user having elevated access to the system.
Patches Update to 4.4.12
Workarounds None
References - https://owasp.org/www-project-top-ten/2017/A72017-Cross-SiteScripting(XSS) - https://owasp.org/www-project-web-security-testing-guide/latest/4-WebApplicationSecurityTesting/07-InputValidationTesting/02-TestingforStoredCrossSiteScripting
If you have any questions or comments about this advisory:
Email us at security@mautic.org
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-qf6m-6m4g-rmrc. This link is maintained to preserve external references.
Original Description Mautic allows you to update the application via an upgrade script.
The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation.
This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.
Summary Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
Patches Please update to 4.4.13 or 5.1.1 or later.
Workarounds None
References https://owasp.org/www-project-top-ten/2017/A72017-Cross-SiteScripting(XSS) https://owasp.org/www-project-web-security-testing-guide/latest/4-WebApplicationSecurityTesting/07-InputValidationTesting/02-TestingforStoredCrossSiteScripting
If you have any questions or comments about this advisory:
Email us at security@mautic.org
Impact Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a Server-Side Request Forgery (SSRF) vulnerability.
Patches Update to 4.4.12 or 5.0.4
Workarounds None
References - https://owasp.org/Top10/A102021-Server-SideRequestForgery%28SSRF%29/
If you have any questions or comments about this advisory:
Email us at security@mautic.org