A cross-site scripting (XSS) vulnerability in the forms component of Mautic prior to 3.2.4 allows remote malicious users to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept).
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
acquia mautic |