ZeroHour

CVE-2020-35124

CVSS 3.1
9.6 critical
EPSS
2%p83
Published
()
Modified
Description

A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.

Vendors
acquia
Products
mautic
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.