


Perceptive Security
SOC/SIEM Consultancy

Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through th…
Published:
5 maart 2026 om 23:00:00
Alert date:
6 maart 2026 om 14:08:47
Source:
nvd.nist.gov
Web Technologies, Database & Storage
Maitra version 1.7.2 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries through the mailid parameter in outmail and inmail modules. The vulnerability also enables attackers to directly download the SQLite database file from the application directory. This results in extraction of sensitive mail tracking data and credentials. The vulnerability affects the mail tracking application and requires authentication to exploit. Multiple proof-of-concept exploits are available publicly.
Technical details
Mitigation steps:
Affected products:
Maitra
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25180
https://www.exploit-db.com/exploits/45841
https://www.vulncheck.com/advisories/maitra-sql-injection-and-database-file-download
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
