Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaigns/clicked/ajax because variable column names are not properly escaped.
{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.24.1"
}
],
"cpe": "cpe:2.3:a:mailtrain:mailtrain:*:*:*:*:*:*:*:*"
}