CVE-2018-11198
- EPSS 0.24%
- Veröffentlicht 06.09.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 03:42:52
An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.
CVE-2017-1000490
- EPSS 0.34%
- Veröffentlicht 03.01.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:51
Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to.
CVE-2017-1000489
- EPSS 0.27%
- Veröffentlicht 03.01.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:51
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
CVE-2017-1000488
- EPSS 0.24%
- Veröffentlicht 03.01.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:50
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.
CVE-2017-8874
- EPSS 0.12%
- Veröffentlicht 10.05.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns or (2) delete contacts.