In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configuration that are used in publicly facing parts of the application.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Mautic
Published: 2021-03-23T19:11:56.967620Z
Updated: 2024-09-16T16:23:48.079Z
Reserved: 2021-03-02T00:00:00
Link: CVE-2021-27908
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2021-03-23T20:15:13.310
Modified: 2024-11-21T05:58:45.650
Link: CVE-2021-27908
 Redhat
                        Redhat
                    No data.