GHSA-gj4p-rxxg-6jhmMedium
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows...
🔗 CVE IDs covered (1)
📋 Description
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-75872
- https://github.com/maalfer/mailerup/commit/da4aedc9621911df4ce0cc8f0b321dd6d10f40a5
- https://github.com/maalfer/mailerup/releases/tag/v1.1.3
- https://secur0.com/en/cna/cve-list/cve-2026-75872-html-injection-in-mailerup-double-optin-verification-email
- https://github.com/advisories/GHSA-gj4p-rxxg-6jhm