PT-2026-77135 · Mailerup · Mailerup

·

CVE-2026-75872

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions maalfer MailerUp versions prior to 1.1.3
Description An HTML injection issue exists in the public subscription form. Unauthenticated remote attackers can cause the application to send a message containing arbitrary HTML to a specified address, appearing to come from the form owner's configured sending identity. This occurs because the first name field of the subscription request is interpolated without escaping into the double opt-in verification email.
Recommendations Update maalfer MailerUp to version 1.1.3 or later. As a temporary mitigation, restrict or sanitize the input of the first name field in the subscription form.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75872

Affected Products

Mailerup