top of page
perceptive_background_267k.jpg

An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an aut…

Published:

28 mei 2026 om 22:00:00

Alert date:

29 mei 2026 om 09:01:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

An SQL injection vulnerability has been discovered in Mautic's API contact filtering mechanism. The vulnerability stems from insufficient recursive sanitization of nested query parameters, allowing authenticated API users to bypass input filtering. Attackers can exploit this flaw to inject arbitrary SQL commands into the database. This represents a significant security risk as it could lead to unauthorized data access, modification, or deletion. The vulnerability affects Mautic's API functionality specifically related to contact filtering operations.

Technical details

Mitigation steps:

Affected products:

Mautic

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page