CVE-2018-10189
Last modified
CVE-2018-10189 is a vulnerability of currently unknown severity. An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies per contact due to tracking the contact by their auto-incremented ID. EPSS estimates a 1.18% chance of exploitation in the next 30 days.
Description
An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies per contact due to tracking the contact by their auto-incremented ID. Thus, a third party can manipulate the cookie value with +1 to systematically assume being tracked as each contact in Mautic. It is then possible to retrieve information about the contact through forms that have progressive profiling enabled.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mautic | Mautic | >= 1.0.0, <= 1.4.1 |
| Mautic | Mautic | >= 2.0.0, < 2.13.0 |
References
- https://github.com/mautic/mautic/releases/tag/2.13.0Third Party Advisory
- https://github.com/mautic/mautic/releases/tag/2.13.0Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10189?
How severe is CVE-2018-10189?
How do I fix CVE-2018-10189?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-10183An issue was discovered in BigTree 4.2.22. There is cross-si…
- CVE-2018-10184An issue was discovered in HAProxy before 1.8.8. The incomin…
- CVE-2018-10185An issue was discovered in TuziCMS v2.0.6. There is a CSRF v…
- CVE-2018-10186In radare2 2.5.0, there is a heap-based buffer over-read in …
- CVE-2018-10187In radare2 2.5.0, there is a heap-based buffer over-read in …
- CVE-2018-10188phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attack…
- CVE-2018-1019A remote code execution vulnerability exists in the way that…
- CVE-2018-10190A vulnerability in London Trust Media Private Internet Acces…
- CVE-2018-10191In versions of mruby up to and including 1.4.0, an integer o…9.8
- CVE-2018-10192IPVanish 3.0.11 for macOS suffers from a root privilege esca…
- CVE-2018-10193LogMeIn LastPass through 4.15.0 allows remote attackers to c…
- CVE-2018-10194The set_text_distance function in devices/vector/gdevpdts.c …
Are you affected by CVE-2018-10189?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
