← לוח פגיעויות

CVE-2026-4776

גבוהה 7.1

תיאור (מקור, אנגלית)

An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.

מדדים

CVSS 3.1
7.1 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-7/8/2026
CWE
CWE-89

קישורים