MEDIUM6.1
GHSA-9hx7-rg7w-xm79
XSS vulnerability in company name field in Mautic
Quick fix
GHSA-9hx7-rg7w-xm79 — mautic/core: upgrade to the fixed version with the command below.
composer require mautic/core:^2.14.0Details
### Impact Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.
### Patches Update to 2.14.0 or later.
### Workarounds None.
### For more information If you have any questions or comments about this advisory: * Email us at [security@mautic.org](mailto:security@mautic.org)
Are you affected?
Enter the version of the package you're using.