SB2021011930 - Multiple vulnerabilities in Mautic



SB2021011930 - Multiple vulnerabilities in Mautic

Published: January 19, 2021 Updated: May 25, 2026

Security Bulletin ID SB2021011930
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Improper Neutralization of Formula Elements in a CSV File (CVE-ID: CVE-2018-8092)

CWE-ID: CWE-1236 - Improper Neutralization of Formula Elements in a CSV File

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to inject formula content into exported contact list CSV files.

The vulnerability exists due to improper neutralization of formula elements in exported CSV content in the contact list export feature when exporting contact lists. A remote user can supply crafted contact data to inject formula content into exported contact list CSV files.

User interaction is required to open the exported CSV file in a spreadsheet application.


2) Cross-site scripting (CVE-ID: CVE-2018-8071)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary script code in a user's browser.

The vulnerability exists due to cross-site scripting in the theme config file when processing crafted theme configuration content. A remote user can supply a specially crafted theme config file to execute arbitrary script code in a user's browser.


3) Improper access control (CVE-ID: CVE-2018-10189)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in tracking cookie handling when processing manipulated tracking cookie values. A remote attacker can modify the cookie value by incrementing the tracked contact identifier to disclose sensitive information.

Information disclosure is possible through forms that have progressive profiling enabled.


Remediation

Install update from vendor's website.