CVE-2020-35125: Mautic core - Highly Critical - XSS vulnerability leveraged through referrers could allow un-authorized admin access

Severity: Critical

CVSS Score: 9.7

A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept).