CVE-2010-3667
TYPO3 is vulnerable to Spam Abuse in the native form content element
5.3
MEDIUM
CVSS 3.1
EPSS 1.1%
Description
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element. An attacker could abuse the form to send mails to arbitrary email addresses.
How to fix CVE-2010-3667
To remediate CVE-2010-3667, upgrade the affected package to a fixed version below.
- Packagist/typo3/cms-frontend—upgrade to 4.1.14 or later
Is CVE-2010-3667 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.1.14
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |