LiveActive security incident?Get immediate response
CVE Record

CVE-2017-1000506: Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name tha...

Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

Mautic 2.11.0 and earlier are reported to allow cross-site scripting through the company name field. If a vulnerable instance is still used, an attacker may cause JavaScript to run in a user's browser and potentially disrupt use. The sources do not provide severity scoring, affected deployment detail, or a named fixed version.

Executive priority

Treat this as a legacy exposure check rather than a confirmed emergency. Prioritize it if Mautic is business-critical, internet-facing, or stores customer marketing data. The absence of severity and exploitation evidence lowers confidence, not the need to inventory.

Technical view

CVE-2017-1000506 describes XSS in Mautic's company name handling for version 2.11.0 and earlier. The reported impact is denial of service and JavaScript execution. Public data in the bundle lacks CVSS, CWE mapping, exploit evidence, and concrete remediation details beyond the upstream issue reference.

Likely exposure

Exposure is likely limited to organizations still running Mautic 2.11.0 or earlier, especially internet-accessible marketing automation portals with editable company data. The bundle does not identify affected CPEs or hosted-service exposure.

Exploitation context

The provided sources do not show CISA KEV listing or active exploitation. The issue is old, published in 2018, but legacy Mautic deployments may remain exposed if they were never upgraded or remediated.

Researcher notes

The record is sparse: no CVSS, CWE, CPE, patch version, or exploit-status evidence is included. Analysis should stay anchored to Mautic 2.11.0 and earlier and the company name XSS claim until upstream issue or release notes confirm more detail.

Mitigation direction

  • Inventory all Mautic deployments and identify versions at or below 2.11.0.
  • Check Mautic vendor guidance and issue history for the appropriate fixed upgrade path.
  • Upgrade affected instances if a supported fixed version is available from Mautic.
  • Restrict administrative access to trusted users while remediation is planned.
  • Review company-name input and rendering paths for proper output encoding.

Validation and detection

  • Confirm whether any production or staging Mautic instance runs version 2.11.0 or earlier.
  • Review Mautic records for unexpected changes to company name fields.
  • Check application logs for suspicious edits involving company profile data.
  • Run only authorized, non-destructive XSS validation in a test environment.
  • Verify remediation by confirming vendor-fixed code or an upgraded Mautic version.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2017-1000506 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.