CVE-2020-35125

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/02/2021
Last modified:
16/02/2021

Description

A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:* 2.16.5 (excluding)
cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:* 3.0.0 (including) 3.2.4 (excluding)