Description
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to version 1.1.3 or higher.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email. | |
| Title | HTML Injection in MailerUp double opt-in verification email | |
| First Time appeared |
Maalfer
Maalfer mailerup |
|
| Weaknesses | CWE-80 | |
| CPEs | cpe:2.3:a:maalfer:mailerup:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Maalfer
Maalfer mailerup |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-08-18T14:06:37.102Z
Reserved: 2026-08-18T12:20:39.352Z
Link: CVE-2026-75872
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses