Mautic是一款开源的营销自动化软件。该软件能够监控管理网站、发送电子邮件并管理客户资源。 Mautic 存在跨站脚本漏洞,该漏洞源于 Mautic 的密码重置页面上存在 XSS 漏洞,其中 URL 中的易受攻击的参数 bundle 可能允许攻击者执行 Javascript 代码。 攻击者需要说服或诱骗目标点击使用易受攻击参数的密码重置 URL。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Mautic before 3.3.4 contains a cross-site scripting vulnerability on the password reset page in the bundle parameter of the URL. An attacker can inject arbitrary script, steal cookie-based authentication credentials, and/or launch other attacks. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-27909.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-27911 | 8.3 HIGH | XSS vulnerability on contacts view |
| CVE-2021-27910 | 8.2 HIGH | Stored XSS vulnerability on Bounce Management Callback |
| CVE-2021-27912 | 7.1 HIGH | XSS vulnerability on asset view |
| CVE-2021-27913 | 3.5 LOW | Use of a Broken or Risky Cryptographic Algorithm |
No comments yet