HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to version 1.1.3 or higher.
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email. | |
| Title | HTML Injection in MailerUp double opt-in verification email | |
| First Time appeared |
Maalfer
Maalfer mailerup |
|
| Weaknesses | CWE-80 | |
| CPEs | cpe:2.3:a:maalfer:mailerup:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Maalfer
Maalfer mailerup |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-08-18T14:06:37.102Z
Reserved: 2026-08-18T12:20:39.352Z
Link: CVE-2026-75872
No data.
Status : Received
Published: 2026-08-18T15:17:15.150
Modified: 2026-08-18T15:17:15.150
Link: CVE-2026-75872
No data.
OpenCVE Enrichment
No data.
Weaknesses