An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.
References
Link Resource
https://github.com/mautic/mautic/releases Release Notes Third Party Advisory
https://github.com/mautic/mautic/releases/tag/2.14.0 Release Notes Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-09-06T20:15:44

Updated: 2019-09-06T20:15:44

Reserved: 2018-05-16T00:00:00


Link: CVE-2018-11198

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-09-06T21:15:11.230

Modified: 2021-01-25T16:51:59.140


Link: CVE-2018-11198

JSON object: View

cve-icon Redhat Information

No data.

CWE