Mautic Version <=3.2.2 Advisory
bishopfox.com | vulnerability | #xss | #vulnerability | #advisory | #mautic | #cve-2020-35128 | #cve-2020-35129
Summary
Stored XSS in Mautic 3.2.2 and earlier (CVE-2020-35128, CVE-2020-35129): users with company or social-monitoring rights can inject JavaScript that runs for admins; fixed in 3.2.4.
- Published
- Collected
Skip to content