CVE-2020-35125
PHP vulnerability analysis and mitigation

Overview

A cross-site scripting (XSS) vulnerability was discovered in the forms component of Mautic before version 3.2.4. The vulnerability, identified as CVE-2020-35125, was discovered in December 2020 and patched in January 2021. The vulnerability affects all versions of Mautic prior to versions 2.16.5 and 3.2.4, allowing remote attackers to inject executable JavaScript via mautic[return] parameter (Mautic Advisory, Github Advisory).

Technical details

The vulnerability exists in the way Mautic handles referrer information in forms. When a lead submits a form or downloads an asset, Mautic captures and stores the HTTP Referer header. A malicious actor could manipulate this header to include an XSS payload, which would then be stored by Mautic and executed when legitimate users view pages where referrer data is displayed. The vulnerability received a CVSS v3.1 base score of 9.6 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H (NVD, Horizon3 Research).

Impact

The vulnerability is considered highly critical with a risk rating of 22/25. When exploited, it allows unauthenticated attackers to gain admin privileges leading to remote code execution on the server hosting Mautic. At the time of discovery, approximately 6,000 instances of Mautic were potentially vulnerable to this attack (Horizon3 Research).

Exploitability

The vulnerability can be exploited by an unauthenticated attacker by manipulating the HTTP Referer header or the mautic[return] form variable to include malicious JavaScript code. When combined with other application features, this could lead to creation of unauthorized admin users and potential remote code execution through custom theme uploads (Horizon3 Research).

Mitigation and workarounds

Users are strongly urged to update to Mautic versions 2.16.5 or 3.2.4 immediately. For those unable to update, patch files are available for both 2.x and 3.x versions. Additionally, administrators can scan their systems for potential exploit attempts by running specific SQL queries to check for suspicious entries in the companies, form submissions, and asset downloads tables (Mautic Advisory).

Community reactions

The Mautic security team responded promptly to the vulnerability report, working with the researchers to develop and release patches within approximately one month of the initial disclosure. The vulnerability was discovered and reported by Naveen Sunkavally at Horizon3.ai, demonstrating effective cooperation between security researchers and the open-source community (Horizon3 Research).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-52777CRITICAL9.4
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52775HIGH8.8
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-86428HIGH8.7
  • PHP logoPHP
  • php-league-commonmark
NoYesSep 07, 2026
CVE-2026-85400HIGH7.5
  • PHP logoPHP
  • composer://typo3/cms-lowlevel
NoYesSep 08, 2026
CVE-2026-77132MEDIUM5.3
  • PHP logoPHP
  • composer://typo3/cms-backend
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management