CVE-2020-35124: Acquia Mautic
Critical severity, CVSS 9.6. EPSS: 2.4% chance of exploitation in the next 30 days.
A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.
Affected products
- Acquia Mautic: before 3.2.4 (fixed in 3.2.4)
Published 2021-01-28. Last modified 2026-06-17.