GHSA-pjpc-87mp-4332
GitHub Security Advisory
Cross-site Scripting vulnerability in Mautic's tracking pixel functionality
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
### Impact
Mautic allows you to track open rates by using tracking pixels.
The tracking information is stored together with extra metadata of the tracking request.
The output isn't sufficiently filtered when showing the metadata of the tracking information, which may lead to a vulnerable situation.
### Patches
Please upgrade to 4.3.0
### Workarounds
None.
### References
* Internally tracked under MST-38
### For more information
If you have any questions or comments about this advisory:
* Email us at [[email protected]](mailto:[email protected])
Affected Packages
Packagist
mautic/core
Affected versions:
0
(fixed in 4.3.0)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.