VDB
Sign up
CRITICAL9.1

GHSA-f683-35w9-28g5

Multiple vulnerabilities in extension "Newsletter subscriber management" (fp_newsletter)

Quick fix

GHSA-f683-35w9-28g5 — fixpunkt/fp-newsletter: upgrade to the fixed version with the command below.

composer require fixpunkt/fp-newsletter:^3.2.6

Details

The CAPTCHA of the extension can be bypassed which may result in automated creation of various newsletter subscribers. It is possible to provide arbitrary subscription UIDs to the `deleteAction` of the extension resulting in all newsletter subscribers to be unsubscribed. Insufficient access checks in the `createAction` and `unsubscribeAction` can be used to obtain data of existing newsletter subscribers.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/fixpunkt/fp-newsletter
Introduced in: 2.2.0Fixed in: 3.2.6
Fixcomposer require fixpunkt/fp-newsletter:^3.2.6
Packagist/fixpunkt/fp-newsletter
Introduced in: 2.0.0Fixed in: 2.1.2
Fixcomposer require fixpunkt/fp-newsletter:^2.1.2
Packagist/fixpunkt/fp-newsletter
Introduced in: 0Fixed in: 1.1.1
Fixcomposer require fixpunkt/fp-newsletter:^1.1.1

References