CVE-2020-35125
09.02.2021, 22:15
A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept).
Vendor | Product | Version |
---|---|---|
acquia | mautic | 𝑥 < 2.16.5 |
acquia | mautic | 3.0.0 ≤ 𝑥 < 3.2.4 |
𝑥
= Vulnerable software versions
References