Skip to main content

CVE-2021-27915

7.6
HIGHCVSS v3.1 Base Score
0.19%
LOW RiskEPSS (41st percentile)

Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions. This could lead to the user having elevated access to the system.

Published: 9/17/2024
Modified: 9/29/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.6HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

EPSS Score (Exploitation Probability)

0.19%LOW Exploitation Risk
41st percentile

This vulnerability has a 0.19% probability of being exploited in the next 30 days, ranking higher than 41% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-80)

CVE-2025-36230MEDIUM 5.4

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

12/26/2025
CVE-2024-52300CRITICAL 9

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact the confidentiality, integrity and availability of the whole XWiki installation when an admin visits the page with the malicious code. This is fixed in 2.5.6.

11/13/2024
CVE-2024-41810MEDIUM 6.1

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.

7/29/2024
CVE-2023-39216CRITICAL 9.6

Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

8/8/2023
CVE-2022-36096HIGH 8.9

The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by anyone viewing the deleted attachments index with an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3. As a workaround, modify fix the vulnerability by editing the wiki page `XWiki.DeletedAttachments` with the object editor, open the `JavaScriptExtension` object and apply on the content the changes that can be found on the fix commit.

9/8/2022

Similar SeverityHIGH