CVE-2022-47411
HIGH7.5EPSS 0.43%"Newsletter subscriber management" (fp_newsletter) TYPO3 extension leaks subscriber data
發布日:2022/12/14修改日:2025/4/21
描述
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations.
受影響套件(1)
- Packagist/fixpunkt/fp-newsletterfrom 0, < 1.1.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |