CVE-2026-75872 PUBLISHED

HTML Injection in MailerUp double opt-in verification email

Assigner: Secur0
Reserved: 18.08.2026 Published: 18.08.2026 Updated: 18.08.2026

HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor maalfer
Product MailerUp
Versions Default: unaffected
  • affected from 0 to 1.1.3 (excl.)

Solutions

Upgrade to version 1.1.3 or higher.

Credits

  • Nacho García Egea finder
  • Xoán M. Otero Jorge analyst
  • Secur0 CNA coordinator
  • Mario Álvarez Fernández remediation developer

References

Problem Types

  • CWE-80 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) CWE

Impacts

  • CAPEC-242 Code Injection