TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2010-3673 | third party advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719 | third party advisory |
https://typo3.org/security/advisory/typo3-sa-2010-012/#Information_Disclosure | vendor advisory |