.. / CVE-2021-27909

Exploit for Mautic <3.3.4 - Cross-Site Scripting (CVE-2021-27909)

Description:

Mautic before 3.3.4 contains a cross-site scripting vulnerability on the password reset page in the bundle parameter of the URL. An attacker can inject arbitrary script, steal cookie-based authentication credentials, and/or launch other attacks.

Nuclei Template

View the template here CVE-2021-27909.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-27909.yaml
Copy

References:

https://github.com/mautic/mautic/security/advisories/GHSA-32hw-3pvh-vcvc
https://github.com/ARPSyndicate/cvemon
https://github.com/ARPSyndicate/kenzer-templates
https://nvd.nist.gov/vuln/detail/CVE-2021-27909