High severity7.6NVD Advisory· Published Sep 17, 2024· Updated Jun 17, 2026
CVE-2021-27915
CVE-2021-27915
Description
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions.
This could lead to the user having elevated access to the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mautic/corePackagist | >= 1.0.0-beta2, < 4.4.12 | 4.4.12 |
Affected products
11>= 1.0.0-beta2+ 9 more
- (no CPE)range: >= 1.0.0-beta2
- cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:*range: >=1.0.0,<4.4.12
- cpe:2.3:a:acquia:mautic:1.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:acquia:mautic:1.0.0:rc4:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.