Impact
A flaw in Mettle SendPortal allows an‑in authorization checks when creating or modifying campaigns. This vulnerability stems from inadequate validation in the CampaignStoreRequest component and can enable an attacker without proper permissions to create or alter campaign data. The weakness corresponds to authorization and privilege escalation issues (CWE-285) and related contextual authorization checks (CWE-639).
Affected Systems
All installations of Mettle SendPortal up to and including version 3.0.1 are affected. The flaw originates in the vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php component of the sendportal‑core package.
Risk and Exploitability
The CVSS score of 5.3 classifies this issue as moderate severity. EPSS scoring is <1%, indicating a low likelihood of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. However, published exploit code demonstrates that an attacker can remotely send crafted requests to the campaign creation endpoint to bypass authorization. The flaw permits unauthorized creation or modification of campaigns, potentially compromising the integrity of campaign data.
OpenCVE Enrichment