HIGH
GHSA-m278-c6gg-4jrr
TYPO3 powermail extension has unrestricted file upload vulnerability
Quick fix
GHSA-m278-c6gg-4jrr — in2code/powermail: upgrade to the fixed version with the command below.
composer require in2code/powermail:^1.6.11Details
Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with a crafted extension, then accessing it via unspecified vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/in2code/powermail
Introduced in:
0Fixed in: 1.6.11Fix
composer require in2code/powermail:^1.6.11Packagist/in2code/powermail
Introduced in:
2.0.0Fixed in: 2.0.14Fix
composer require in2code/powermail:^2.0.14