The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checking of authentication codes.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-014/ | vendor advisory |
https://extensions.typo3.org/extension/direct_mail/ | release notes product vendor advisory |
http://www.openwall.com/lists/oss-security/2014/09/11/4 | issue tracking mailing list |