VDB
Sign up
HIGH

GHSA-m278-c6gg-4jrr

TYPO3 powermail extension has unrestricted file upload vulnerability

Quick fix

GHSA-m278-c6gg-4jrr — in2code/powermail: upgrade to the fixed version with the command below.

composer require in2code/powermail:^1.6.11

Details

Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with a crafted extension, then accessing it via unspecified vectors.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/in2code/powermail
Introduced in: 0Fixed in: 1.6.11
Fixcomposer require in2code/powermail:^1.6.11
Packagist/in2code/powermail
Introduced in: 2.0.0Fixed in: 2.0.14
Fixcomposer require in2code/powermail:^2.0.14

References