An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations.
References
Link | Resource |
---|---|
https://typo3.org/security/advisory/typo3-ext-sa-2022-017 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-12-14 13:15
Updated : 2022-12-16 14:11
NVD link : CVE-2022-47410
Mitre link : CVE-2022-47410
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
fp_newsletter_project
- fp_newsletter