Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.
Upgrade to 2.12.0 or later.
None
https://github.com/mautic/mautic/releases/tag/2.12.0
If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2021-01-19T21:14:13Z",
"nvd_published_at": "2018-01-03T16:29:00Z",
"severity": "MODERATE"
}