PSA-2026-G1CT26GCVE-125-2026-G1CT26August 15, 20265.4 Medium
DMARC not enabled for postiz.com
Postiz has not enabled DMARC on their primary domain, resulting to email forgery.
Affected (1)
- GitroomHQpostiz-cloud
- ≥ 0Fixed in 0.1Affected
All other versions: Affected
Overview
Postiz is an open-source social media scheduler. This advisory is exclusively for the Postiz Cloud environment. The DMARC record of 'postiz.com' has been set to 'none', resulting it to be disabled. This would allow forgery or our email's, with no Spam-Filter blocking it on the client-side.
Severity
CVSS v3
5.4 Medium
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- Low
- Availability
- Low
Weaknesses (1)
References (1)
- DMARC of Postiz (Related)
Credits (3)
- Muhammad WaqasReporter · @Waqas-105
- Enno GelhausCoordinator · @egelhaus
- Nevo DavidRemediation developer · @nevo-david
Context
Impacts
Anybody was able to send emails from any postiz.com E-Mail, resulting in loss of trust to Postiz.