Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTloeDctcmc3dy14bTc5

XSS vulnerability in company name field in Mautic

Impact

Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.

Patches

Update to 2.14.0 or later.

Workarounds

None.

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-9hx7-rg7w-xm79
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTloeDctcmc3dy14bTc5
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 3 years ago
Updated: 11 months ago


CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Identifiers: GHSA-9hx7-rg7w-xm79, CVE-2018-11200
References:

Affected Packages

packagist:mautic/core
Versions: < 2.11.0
Fixed in: 2.14.0