Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mailerup <1.0.0 on all platforms allows remote unauthenticated attackers to redirect victims to arbitrary external sites and conduct phishing attacks via a crafted u query parameter, because the URL scheme is validated (blocking javascript: and data:) but the destination host is not restricted to an allowlist, and a signing.BadSignature exception is silently caught so a valid signed token is not required.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Jun 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mailerup <1.0.0 on all platforms allows remote unauthenticated attackers to redirect victims to arbitrary external sites and conduct phishing attacks via a crafted u query parameter, because the URL scheme is validated (blocking javascript: and data:) but the destination host is not restricted to an allowlist, and a signing.BadSignature exception is silently caught so a valid signed token is not required. | |
| Title | Lack of input validation in Mailerup input parameter leads to Open Redirect | |
| First Time appeared |
Mailerup
Mailerup mailerup |
|
| Weaknesses | CWE-601 | |
| CPEs | cpe:2.3:a:mailerup:mailerup:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mailerup
Mailerup mailerup |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-06-24T13:07:07.003Z
Reserved: 2026-06-24T12:44:34.692Z
Link: CVE-2026-13163
Updated: 2026-06-24T13:07:01.543Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T15:30:17Z