{"id":"CVE-2020-35124","aliases":["GHSA-39wj-j3jc-858m"],"url":"https://o3.security/vulnerability/CVE-2020-35124","summary":"XSS vulnerability leveraged through referrers could allow un-authorized admin access in Mautic","details":"A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.","published":"2021-01-28T06:15:13.373Z","modified":"2026-08-07T15:12:33.892825Z","cvss":{"score":9.6,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"mautic/core","fixedVersion":"3.2.4"},{"ecosystem":"Packagist","name":"mautic/core","fixedVersion":"2.16.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://forum.mautic.org/c/announcements/16"},{"type":"ADVISORY","url":"https://github.com/mautic/mautic/security/advisories/GHSA-39wj-j3jc-858m"},{"type":"ADVISORY","url":"https://www.horizon3.ai/disclosures/mautic-unauth-xss-to-rce"},{"type":"ADVISORY","url":"https://www.mautic.org/blog/community/security-release-all-versions-mautic-prior-2-16-5-and-3-2-4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:12:33.892825Z"}}