SB2021032238 - Information disclosure in Mautic
Published: March 22, 2021 Updated: May 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Information disclosure (CVE-ID: CVE-2021-27908)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in free text configuration fields rendered in publicly facing parts of the application when referencing Symfony parameters in configuration content. A local privileged user can enter crafted parameter references into a free text configuration field to disclose sensitive information.
User interaction is required to visit a page that renders the crafted content.
Remediation
Install update from vendor's website.