CVE-2026-54822
SALESmanago · SALESmanago & Leadoo
A SQL injection vulnerability exists in the SALESmanago & Leadoo plugin, allowing authenticated subscribers to execute arbitrary SQL commands via the application.
Executive summary
The SALESmanago & Leadoo plugin is vulnerable to an authenticated SQL injection flaw that could allow malicious actors to compromise the underlying application database.
Vulnerability
The vulnerability is a subscriber-level SQL injection, meaning an authenticated user with subscriber privileges can manipulate database queries. This occurs due to insufficient sanitization of user-supplied input before it is processed by the database.
Business impact
Successful exploitation can lead to unauthorized data extraction, modification, or deletion of sensitive customer and platform information. With a CVSS score of 8.5, this high-severity flaw threatens the overall integrity of the application and could result in severe data breaches.
Remediation
Immediate Action: Update the SALESmanago & Leadoo plugin to the latest version provided by the vendor.
Proactive Monitoring: Enable database query logging and monitor for unusual query patterns or syntax errors that suggest injection attempts.
Compensating Controls: Utilize a Web Application Firewall (WAF) with SQL injection protection rules to block malicious payloads targeting the vulnerable parameters.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Security teams should immediately audit user access levels and apply the necessary patches. Given the potential for full database compromise, this update should be treated as a high-priority task to ensure the integrity of the marketing automation platform.