top of page
perceptive_background_267k.jpg

Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through th…

Published:

5 maart 2026 om 23:00:00

Alert date:

6 maart 2026 om 14:08:47

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

Maitra version 1.7.2 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries through the mailid parameter in outmail and inmail modules. The vulnerability also enables attackers to directly download the SQLite database file from the application directory. This results in extraction of sensitive mail tracking data and credentials. The vulnerability affects the mail tracking application and requires authentication to exploit. Multiple proof-of-concept exploits are available publicly.

Technical details

Mitigation steps:

Affected products:

Maitra

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page