CVE Database
/

CVE-2021-24288

Back to search

CVE-2021-24288

Published: May 17, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.

VendorProductVersions

AcyMailing

Newsletter via SMTP, Sendinblue, Sendgrid, Mailgun - AcyMailing SMTP Newsletter

affected
7.5.0 - < 7.5.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now