Vulnerability CVE-2021-27908


Published: 2021-03-23

Description:
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic??s configuration that are used in publicly facing parts of the application.

Type:

CWE-732

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Acquia -> Mautic 

 References:
https://github.com/mautic/mautic/security/advisories/GHSA-4hjq-422q-4vpx

Copyright 2024, cxsecurity.com

 

Back to Top