CVE-2020-35124: Acquia Mautic

Critical severity, CVSS 9.6. EPSS: 2.4% chance of exploitation in the next 30 days.

A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.

Affected products

  • Acquia Mautic: before 3.2.4 (fixed in 3.2.4)

Published 2021-01-28. Last modified 2026-06-17.