Mautic Self XSS Vulnerability
CVE-2022-25774

5.4MEDIUM

Key Information:

Vendor

Mautic

Status
Vendor
CVE Published:
18 September 2024

What is CVE-2022-25774?

Logged-in users of Mautic can exploit a self XSS vulnerability due to insufficient input validation within the notification feature. This allows attackers to inject custom scripts when saving dashboards, potentially leading to unauthorized actions or data breaches. Proper security measures and timely updates are essential to mitigate this risk.

Affected Version(s)

Mautic < 4.4.12

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vautia
Lenon Leite
Zdeno Kuzmany
John Linhart
.