
Mautic self-hosters: CVE-2018-8092 is CVSS 9.8 (critical). Attack: formula injected via contact form, staff exports CSV, opens in Excel, formula runs. Fix: upgrade to Mautic 2.13.0+. https://insights.cloudgeeks.com.au/blog/mautic-csv-injection-cve-2018-8092/ https://t.co/qS31S5qxxI
Post summary
The post announces CVE‑2018‑8092 as a critical flaw in Mautic that allows attackers to inject executable formulas through the contact form; it cites the CVSS score and urges an upgrade to Mautic 2.13.0+ to remediate the issue.
