VDB
Sign up
MEDIUM6.3

GHSA-32hw-3pvh-vcvc

XSS vulnerability on password reset page

Quick fix

GHSA-32hw-3pvh-vcvc — mautic/core: upgrade to the fixed version with the command below.

composer require mautic/core:^3.3.4

Details

### Impact For Mautic versions prior to 3.3.4, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in the URL could allow an attacker to execute Javascript code. The attacker would be required to convince or trick the target into clicking a password reset URL with the vulnerable parameter utilized.

### Patches

Upgrade to 3.3.4 or 4.0.0

### Workarounds

No

### References

https://github.com/mautic/mautic/releases/tag/3.3.4 https://github.com/mautic/mautic/releases/tag/4.0.0

### For more information If you have any questions or comments about this advisory: * Email us at [security@mautic.org](mailto:security@mautic.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mautic/core
Introduced in: 0Fixed in: 3.3.4
Fixcomposer require mautic/core:^3.3.4
Packagist/mautic/core
Introduced in: 4.0.0-alpha1Fixed in: 4.0.0
Fixcomposer require mautic/core:^4.0.0

References