Symfony Mailjet Mailer
- >= 6.4, < 6.4.40
- >= 7.0, < 7.4.12
- >= 8.0, < 8.0.12
A vulnerability exists in the Symfony Mailjet mailer bridge and LOX24 notifier bridge webhook parsers, prior to versions 6.4.40, 7.4.12, and 8.0.12. The parsers received configured webhook secrets but failed to verify them, allowing unauthenticated POST requests to inject forged event payloads. This lack of verification could lead to the corruption of suppression lists and manipulation of delivery metrics.
Exploitation of this vulnerability allows for unauthenticated injection of forged webhook event payloads, which can corrupt suppression lists and fraudulently alter delivery metrics.
To reproduce this vulnerability, configure a webhook secret for either the Mailjet mailer or LOX24 notifier bridge. Then, send a POST request to the webhook endpoint without including the expected authentication credentials or token. The webhook parser will accept the request and process the injected event payload, demonstrating the lack of secret verification.
This vulnerability has been patched in Symfony versions 6.4.40, 7.4.12, and 8.0.12. Users should update to these versions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.