Skip to content

XSS vulnerability in company name field

Moderate
RCheesley published GHSA-9hx7-rg7w-xm79 Jan 19, 2021

Package

composer mautic/core (Composer)

Affected versions

< 2.11.0

Patched versions

2.14.0

Description

Impact

Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.

Patches

Update to 2.14.0 or later.

Workarounds

None.

References

https://github.com/mautic/mautic/releases/tag/2.14.0

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2018-11200

Weaknesses

No CWEs

Credits