CVE-2021-27908 - CVE House
Back to Database
Status published Medium CVE-2021-27908

In all versions prior to Mautic 3.3.2, secret parameters such...

Vulnerability Description

In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configuration that are used in publicly facing parts of the application.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-27908

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Discovered by Petr Gregor, Acquia
  • Fixed by Miroslav Fedeles, Acquia

Affected Vendor

Affected Software

Mautic
Vulnerable Versions:
unspecified

Timeline

Official Publish: March 23rd, 2021
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L

Weaknesses (CWE)