S4E just found a high-severity finding from directory listing vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2021-24288

6.1
CVSS
Description

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.

Attack Vector
-
Privileges Req.
-
User Interaction
-
newsletter via smtp, sendinblue, sendgrid, mailgun - acymailing smtp newsletter
Updated Sep 26, 2026View on NVD →
S4E scanner

CVE history: newsletter via smtp, sendinblue, sendgrid, mailgun - acymailing smtp newsletter

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →