Junglewise Threat Intelligence

CVE-2025-7702: Pusula Manageable Email Sending System open redirect

CVE-2025-7702 · Severity: medium · CVSS 4.7 · Published 2025-09-19

Executive brief

The Manageable Email Sending System by Pusula contains a security flaw that allows attackers to redirect users to malicious websites. This is typically achieved by sending a legitimate-looking link that, when clicked, forwards the user to a site controlled by the attacker. This can be used in phishing campaigns to steal login credentials or distribute malware by exploiting the user's trust in the original domain.

Technical details

An Open Redirect vulnerability (CWE-601) exists in the Pusula Manageable Email Sending System due to improper validation of user-supplied input used in URL redirection. A remote, unauthenticated attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external domain. This vulnerability requires user interaction (clicking a link) and can be leveraged to facilitate phishing attacks or bypass security filters that rely on domain whitelisting. The issue is fixed in versions released on or after August 6, 2025.

Affected products

  • Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System <=2025.06 before 2025.08.06

Timeline

  • 2025-08-06: patched: Fix released in version 2025.08.06
  • 2025-09-19: disclosed: Initial advisory publication

References