RULE(RULE ID:336662)

Rule General Information
Release Date: 2022-06-21
Rule Name: Acquia Mautic Tracking Pixel Stored Cross Site Scripting Vulnerability (CVE-2022-25772)
Severity:
CVE ID:
Rule Protection Details
Description: A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Others
Reference: https://github.com/mautic/mautic/security/advisories/GHSA-pjpc-87mp-4332
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.