Mautic kayıtları
mautic üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %81,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2018-8092İstismar yok | Mautic before 2.13.0 allows CSV injection.mautic · mautic · CWE-1236 | Kritik9,8 | — | %1,6 | 18 Nis 2018 |
36İzleyin | CVE-2020-35129İstismar yok | Mautic before 3.2.4 is affected by stored XSS.mautic · mautic · CWE-79 | Kritik9,0 | — | %1,0 | 19 Oca 2021 |
32İzleyin | CVE-2017-1000489İstismar yok | Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email addressmautic · mautic · CWE-287 | Yüksek8,1 | — | %1,1 | 3 Oca 2018 |
30İzleyin | CVE-2018-10189İstismar yok | An issue was discovered in Mautic 1.x and 2.x before 2.13.0.mautic · mautic · CWE-200 | Yüksek7,5 | — | %1,1 | 17 Nis 2018 |
30İzleyin | CVE-2017-1000046İstismar yok | Mautic 2.6.1 and earlier fails to set flags on session cookiesmautic · mautic | Yüksek7,5 | — | %1,1 | 17 Tem 2017 |
26İzleyin | CVE-2017-1000490İstismar yok | Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanmautic · mautic · CWE-22 | Orta6,5 | — | %1,4 | 3 Oca 2018 |
24İzleyin | CVE-2017-1000506İstismar yok | Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of servicemautic · mautic · CWE-79 | Orta6,1 | — | %1,1 | 9 Şub 2018 |
24İzleyin | CVE-2017-1000488İstismar yok | Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parametersmautic · mautic · CWE-79 | Orta6,1 | — | %0,8 | 3 Oca 2018 |
24İzleyin | CVE-2018-8071İstismar yok | Mautic before v2.13.0 has stored XSS via a theme config file.mautic · mautic · CWE-79 | Orta6,1 | — | %0,8 | 18 Nis 2018 |
21İzleyin | CVE-2024-2730İstismar yok | Predictable Page Indexing Might Lead to Sensitive Data Exposure in Mauticmautic · mautic · CWE-425 | Orta5,3 | — | %0,5 | 10 Nis 2024 |
20İzleyin | CVE-2024-3448İstismar yok | Improper Access Control Leads to Server-Side Request Forgery in Mauticmautic · mautic · CWE-918 | Orta5,0 | — | %0,4 | 10 Nis 2024 |
- CVE-2018-809239İzleyin
Mautic before 2.13.0 allows CSV injection.
KritikCVSS 9,8İstismar yokEPSS %2mautic · mautic18 Nis 2018
- CVE-2020-3512936İzleyin
Mautic before 3.2.4 is affected by stored XSS.
KritikCVSS 9,0İstismar yokEPSS %1mautic · mautic19 Oca 2021
- CVE-2017-100048932İzleyin
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
YüksekCVSS 8,1İstismar yokEPSS %1mautic · mautic3 Oca 2018
- CVE-2018-1018930İzleyin
An issue was discovered in Mautic 1.x and 2.x before 2.13.0.
YüksekCVSS 7,5İstismar yokEPSS %1mautic · mautic17 Nis 2018
- CVE-2017-100004630İzleyin
Mautic 2.6.1 and earlier fails to set flags on session cookies
YüksekCVSS 7,5İstismar yokEPSS %1mautic · mautic17 Tem 2017
- CVE-2017-100049026İzleyin
Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Fileman
OrtaCVSS 6,5İstismar yokEPSS %1mautic · mautic3 Oca 2018
- CVE-2017-100050624İzleyin
Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service
OrtaCVSS 6,1İstismar yokEPSS %1mautic · mautic9 Şub 2018
- CVE-2017-100048824İzleyin
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters
OrtaCVSS 6,1İstismar yokEPSS %1mautic · mautic3 Oca 2018
- CVE-2018-807124İzleyin
Mautic before v2.13.0 has stored XSS via a theme config file.
OrtaCVSS 6,1İstismar yokEPSS %1mautic · mautic18 Nis 2018
- CVE-2024-273021İzleyin
Predictable Page Indexing Might Lead to Sensitive Data Exposure in Mautic
OrtaCVSS 5,3İstismar yokEPSS %1mautic · mautic10 Nis 2024
- CVE-2024-344820İzleyin
Improper Access Control Leads to Server-Side Request Forgery in Mautic
OrtaCVSS 5,0İstismar yokEPSS %0mautic · mautic10 Nis 2024