SB2021011930 - Multiple vulnerabilities in Mautic
Published: January 19, 2021 Updated: May 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Improper Neutralization of Formula Elements in a CSV File (CVE-ID: CVE-2018-8092)
CWE-ID: CWE-1236 - Improper Neutralization of Formula Elements in a CSV File
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to inject formula content into exported contact list CSV files.
The vulnerability exists due to improper neutralization of formula elements in exported CSV content in the contact list export feature when exporting contact lists. A remote user can supply crafted contact data to inject formula content into exported contact list CSV files.
User interaction is required to open the exported CSV file in a spreadsheet application.
2) Cross-site scripting (CVE-ID: CVE-2018-8071)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script code in a user's browser.
The vulnerability exists due to cross-site scripting in the theme config file when processing crafted theme configuration content. A remote user can supply a specially crafted theme config file to execute arbitrary script code in a user's browser.
3) Improper access control (CVE-ID: CVE-2018-10189)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in tracking cookie handling when processing manipulated tracking cookie values. A remote attacker can modify the cookie value by incrementing the tracked contact identifier to disclose sensitive information.
Information disclosure is possible through forms that have progressive profiling enabled.
Remediation
Install update from vendor's website.