PT-2026-1133 · Listmonk · Listmonk

Playeriunknown

·

Publicado

2026-01-02

·

Atualizado

2026-01-17

·

CVE-2026-21483

CVSS v4.0

6.4

Média

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions listmonk versions prior to 6.0.0
Description listmonk is a self-hosted newsletter and mailing list manager. A user with campaign management permissions, but lower privileges, can inject malicious JavaScript into campaigns or templates. When a user with higher privileges (Super Admin) views or previews this content, the JavaScript executes in their browser, potentially allowing the attacker to perform privileged actions, such as creating backdoor admin accounts. The issue can be exploited through the public archive feature, requiring only a link visit from the victim, without needing to preview the content. The vulnerable component is the campaign or template functionality.
Recommendations Update to version 6.0.0 or later.

Exploit

Correção

LPE

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21483
GHSA-JMR4-P576-V565
GO-2026-4277
SUSE-SU-2026:0142-1

Produtos afetados

Listmonk