{"id":"CVE-2022-25774","aliases":["GHSA-fhcx-f7jg-jx3f"],"url":"https://o3.security/vulnerability/CVE-2022-25774","summary":"XSS in Notifications via saving Dashboards","details":"### Impact\nPrior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic.\n\nUsers could inject malicious code into the notification when saving Dashboards.\n\n### Patches\nUpdate to Mautic 4.4.12. \n\n### Workarounds\nNone\n\n### References\n- https://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS)\n\nIf you have any questions or comments about this advisory:\n\nEmail us at [security@mautic.org](mailto:security@mautic.org)","published":"2024-09-18T14:54:36.249Z","modified":"2026-08-12T03:51:19.110296930Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"mautic/core","fixedVersion":"4.4.12"}],"fix":{"url":"https://github.com/mautic/mautic/commit/e6d58de241b8c34126042dcb314d60eb5fc7b151","label":"mautic/mautic@e6d58de"},"references":[{"type":"WEB","url":"https://packagist.org"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25774.json"},{"type":"ADVISORY","url":"https://github.com/mautic/mautic/security/advisories/GHSA-fhcx-f7jg-jx3f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25774"},{"type":"PACKAGE","url":"https://github.com/mautic/mautic"},{"type":"WEB","url":"https://github.com/mautic/mautic/commit/e6d58de241b8c34126042dcb314d60eb5fc7b151"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:19.110296930Z"}}