Executive brief
Mautic, an open-source marketing automation platform, contains a security vulnerability in its project management feature. An attacker with basic user permissions can save a malicious script as a project name. When an administrator later views this project, the script executes in their browser, potentially allowing the attacker to steal session information, access sensitive organizational data, or perform actions on behalf of the administrator.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. The root cause is a failure to sanitize project names returned via AJAX before they are injected into the DOM as option fields within selection menus. An authenticated attacker with 'create project' permissions can inject a malicious payload into a project name. When an administrative user opens an entity editor that loads this project selector, the payload executes in their session context (CWE-79). This can lead to session hijacking or unauthorized data access. The issue is fixed in version 7.1.2.
Affected products
- Mautic Mautic Core >= 7.0.0, < 7.1.2
Timeline
- 2026-05-29: disclosed: NVD publication date
- 2026-07-02: advisory: GitHub Advisory published
- 2026-07-02: patched: Version 7.1.2 released
References
- https://api.github.com/users/pavelkohout396
- https://github.com/pavelkohout396
- https://api.github.com/users/pavelkohout396/gists%7B/gist_id%7D
- https://api.github.com/users/pavelkohout396/repos
- https://avatars.githubusercontent.com/u/192136750?v=4
- https://api.github.com/users/pavelkohout396/events%7B/privacy%7D