CVE-2026-54822

SALESmanago · SALESmanago & Leadoo

A SQL injection vulnerability exists in the SALESmanago & Leadoo plugin, allowing authenticated subscribers to execute arbitrary SQL commands via the application.

Executive summary

The SALESmanago & Leadoo plugin is vulnerable to an authenticated SQL injection flaw that could allow malicious actors to compromise the underlying application database.

Vulnerability

The vulnerability is a subscriber-level SQL injection, meaning an authenticated user with subscriber privileges can manipulate database queries. This occurs due to insufficient sanitization of user-supplied input before it is processed by the database.

Business impact

Successful exploitation can lead to unauthorized data extraction, modification, or deletion of sensitive customer and platform information. With a CVSS score of 8.5, this high-severity flaw threatens the overall integrity of the application and could result in severe data breaches.

Remediation

Immediate Action: Update the SALESmanago & Leadoo plugin to the latest version provided by the vendor.

Proactive Monitoring: Enable database query logging and monitor for unusual query patterns or syntax errors that suggest injection attempts.

Compensating Controls: Utilize a Web Application Firewall (WAF) with SQL injection protection rules to block malicious payloads targeting the vulnerable parameters.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Security teams should immediately audit user access levels and apply the necessary patches. Given the potential for full database compromise, this update should be treated as a high-priority task to ensure the integrity of the marketing automation platform.