Mautic allows you to track open rates by using tracking pixels.
The tracking information is stored together with extra metadata of the tracking request.
The output isn't sufficiently filtered when showing the metadata of the tracking information, which may lead to a vulnerable situation.
Please upgrade to 4.3.0
None.
If you have any questions or comments about this advisory:
* Email us at [email protected]
| Score | Percentile |
|---|---|
| 2.07% | 83.77% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 9.6 | 3.1 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-pjpc-87mp-4332 ↗ |
| CVE | CVE-2022-25772 ↗ |
| CWE id | Name |
|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| composer | mautic/core | < 4.3.0 | 4.3.0 | — |