Showing 1 vulnerability on this page for Newsletter via SMTP, Sendinblue, Sendgrid, Mailgun - AcyMailing SMTP Newsletter

Signals CISA KEV Ransomware Nuclei
AcyMailing vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

AcyMailing < 7.5.0 - Unauthenticated Open Redirect

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.

CWE-601May 17, 20211 related artifact
CVSS6.1v3.1EPSS1.94%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX