Cross-Site Scripting Vulnerability in Mettle Sendportal by Mettle
CVE-2026-10234
Key Information:
- Vendor
Mettle
- Status
- Vendor
- CVE Published:
- 1 June 2026
Badges
What is CVE-2026-10234?
A cross-site scripting vulnerability has been identified in Mettle Sendportal, specifically in the campaign handler component located within the /webview/ section. This vulnerability allows remote attackers to manipulate content arguments, which may lead to unauthorized script execution in the user's browser. This issue was reported to the developers, but as of now, they have not issued a response. The public confirmation of this exploit emphasizes the urgency for users to apply necessary precautions.
Affected Version(s)
sendportal 3.0.0
sendportal 3.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
