Beveiligingsadvies

CVE-2021-27909

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-08-30 16:00:10
Laatst bijgewerkt 2024-09-16 20:52:58
Toegewezen door Mautic
CVSS-score 6.3
Status PUBLISHED

Beschrijving

For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in the URL could allow an attacker to execute Javascript code. The attacker would be required to convince or trick the target into clicking a password reset URL with the vulnerable parameter utilized.