Cross-site scripting in Mautic - CVE-2021-27914
Published: May 23, 2022 / Updated: May 25, 2026
Mautic
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to cross-site scripting in the installer when processing install information input. A remote privileged user can submit crafted install information to execute arbitrary script in a user's browser.
User interaction is required, and exploitation is limited to the installation process.