Skip to main content

Vendor/product archive

dkd / direct_mail CVEs

Beta · best-effort

6 CVEs tagged to dkd / direct_mail0 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2020-12700

Published May 13, 2020

The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special Query.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12699

Published May 13, 2020

The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12698

Published May 13, 2020

The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber tables.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12697

Published May 13, 2020

The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16698

Published Oct 16, 2019

The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7400

Published Dec 29, 2017

The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checking of authentication codes.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1