SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2023-50461

HIGH · CVSS 8.8 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The direct_mail extension for TYPO3 versions up to 9.5.1 is vulnerable, allowing authenticated users to modify TSConfig pages for folders configured as Direct Mail. This can lead to configuration injection in TYPO3 10.4 and above, or arbitrary code execution in versions 9.5 and below. Organizations using TYPO3 with the direct_mail extension should prioritize patching this vulnerability to mitigate the risk of unauthorized access and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2023-50461
Severity
HIGH
CVSS
8.8
EPSS
0.33%

Original NVD Description

An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend user account, with access to the Direct Mail Configuration backend module, is needed to exploit this.