Impact
A vulnerability in the APIv1 Webhooks of Mettle Sendportal allows remote attackers to bypass authentication for the sendgrid, postmark, postal, and mailjet endpoints. The flaw is rooted in improper authentication handling (CWE‑287) and missing authentication checks (CWE‑306). The attacker can manipulate requests to trigger webhook handlers without valid credentials, potentially causing unintended service behavior, unauthorized data exposure, or denial of related services. The attack is possible to be carried out remotely by crafting requests directly to these endpoints over HTTP.
Affected Systems
The flaw affects the sendportal application of the vendor Mettle, specifically versions up to and including 3.0.1. Any deployment that exposes the APIv1 Webhooks endpoints (sendgrid, postmark, postal, mailjet) is at risk, regardless of host configuration.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate to high severity. The publicly disclosed exploit may be available, and the attack is remote. The EPSS score of <1% indicates a very low likelihood of exploitation today. The flaw is not listed in CISA’s KEV catalog, suggesting it is not yet known to be exploited in the wild. Attackers would need to identify an exposed APIv1 Webhooks endpoint with no authentication, then send crafted requests via the network to trigger the vulnerable handler.
OpenCVE Enrichment