In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade directmailteam/direct-mail
to version 6.0.3, 7.0.3, 9.5.2 or higher.
directmailteam/direct-mail is an advanced Direct Mail/Newsletter mailer system with sophisticated options for personalization of emails including response statistics.
Affected versions of this package are vulnerable to External Control of System or Configuration Setting. The “Configuration” backend module of the extension allows an authenticated user to write arbitrary page TSConfig for folders configured as “Direct Mail”.
Note:
A valid backend user account having access to the Direct Mail "Configuration" backend module is needed in order to exploit this vulnerability.
Users of the extension should manually check if a suspicious page TSConfig has been written to all folders configured as “Direct Mail”.
Exploiting this vulnerability might lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below).