CVE-2017-1000488
03.01.2018, 16:29
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.
| Vendor | Product | Version |
|---|---|---|
| acquia | mautic | 2.1.0 |
| acquia | mautic | 2.1.1 |
| acquia | mautic | 2.2.0 |
| acquia | mautic | 2.2.1 |
| acquia | mautic | 2.3.0 |
| acquia | mautic | 2.4.0 |
| acquia | mautic | 2.5.0 |
| acquia | mautic | 2.5.1 |
| acquia | mautic | 2.6.0 |
| acquia | mautic | 2.6.1 |
| acquia | mautic | 2.7.0 |
| acquia | mautic | 2.7.1 |
| acquia | mautic | 2.8.0 |
| acquia | mautic | 2.8.1 |
| acquia | mautic | 2.8.2 |
| acquia | mautic | 2.9.0:beta |
| acquia | mautic | 2.9.1 |
| acquia | mautic | 2.10.0:beta |
| acquia | mautic | 2.10.1 |
| acquia | mautic | 2.11.0:beta |
| mautic | mautic | 2.9.0 |
| mautic | mautic | 2.9.2 |
| mautic | mautic | 2.10.0 |
| mautic | mautic | 2.11.0 |
𝑥
= Vulnerable software versions