Cross-site Scripting (XSS) - stored (edit form HTML field)
Vulnerability Description
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47058
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- MatisAct
- Lenon Leite
- John Linhart
- Avikarsha Saha
More from Mautic
View All →Affected Vendor
Mautic
View all reports →