MEDIUM4.3
GHSA-j2w4-45qm-r674
direct_mail for Typo3 sensitive data exposure
Quick fix
GHSA-j2w4-45qm-r674 — directmailteam/direct-mail: upgrade to the fixed version with the command below.
composer require directmailteam/direct-mail:^5.2.3Details
The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users table) to view and export data of frontend users who are subscribed to a newsletter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/directmailteam/direct-mail
Introduced in:
0Fixed in: 5.2.3Fix
composer require directmailteam/direct-mail:^5.2.3References
- https://nvd.nist.gov/vuln/detail/CVE-2019-16698[ADVISORY]
- https://github.com/kartolo/direct_mail/commit/3a70924777294c7fb40e9f6eb3f7627bac58dfd1[WEB]
- https://extensions.typo3.org/extension/direct_mail[WEB]
- https://github.com/kartolo/direct_mail[PACKAGE]
- https://typo3.org/security/advisory/typo3-ext-sa-2019-016[WEB]