Back

MEDIUM

Improper Access Control Leads to Server-Side Request Forgery in Mautic

Published Apr 10, 2024

Description

Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeAvailability leads to a Server-Side Request Forgery by analyzing the error messages returned from the back-end. Allowing an attacker to perform a port scan in the back-end. At the time of publication of the CVE no patch is available.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner NCSC.ch
Published Apr 10, 2024
Updated Aug 1, 2024
Reserved Apr 8, 2024
CISA Vulnrichment
Updated Apr 11, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner NCSC.ch
Published Apr 10, 2024
Updated Aug 1, 2024
Exploited since n/a
EUVD-2024-32035