-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| mautic/core | composer | < 3.3.4 | 3.3.4 |
| mautic/core | composer | >= 4.0.0-alpha1, < 4.0.0 | 4.0.0 |
The vulnerability stems from unescaped contact names being rendered in JavaScript contexts. Key indicators:
While exact code isn't available, Mautic's architecture suggests:
Ongoing coverage of React2Shell