Description
A vulnerability was detected in Mettle sendportal up to 3.0.1. This affects an unknown part of the file /webview/ of the component Campaign Handler. The manipulation of the argument content results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Problem types
Product status
3.0.1
Timeline
| 2026-05-02: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-06-02: | VulDB entry last update |
Credits
Kabilan D
B1scuit (VulDB User)
Superman_04 (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/367513 (VDB-367513 | Mettle sendportal Campaign webview cross site scripting)
vuldb.com/vuln/367513/cti (VDB-367513 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10234 (CVE-2026-10234 | CVE Analysis and Report)
vuldb.com/submit/822923 (Submit #822923 | Mettle sendportal v3.0.1 Cross Site Scripting)
vuldb.com/submit/825494 (Submit #825494 | mettle sendportal 3.0.1 Cross Site Scripting (Duplicate))
github.com/mettle/sendportal/issues/338
github.com/mettle/sendportal/