CVE-2010-0329
TYPO3 powermail Extension Vulnerable to SQL Injection via Unspecified Vectors
EPSS 1.1%
Description
SQL injection vulnerability in the powermail extension 1.5.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to the "SQL selection field" and "typoscript."
How to fix CVE-2010-0329
To remediate CVE-2010-0329, upgrade the affected package to a fixed version below.
- Packagist/in2code/powermail—upgrade to 1.5.2 or later
Is CVE-2010-0329 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.5.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |