CyberRota Analysis
AI-GeneratedThe direct_mail extension for TYPO3 versions up to 9.5.1 is vulnerable, allowing authenticated users to modify TSConfig pages for folders configured as Direct Mail. This can lead to configuration injection in TYPO3 10.4 and above, or arbitrary code execution in versions 9.5 and below. Organizations using TYPO3 with the direct_mail extension should prioritize patching this vulnerability to mitigate the risk of unauthorized access and potential system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend user account, with access to the Direct Mail Configuration backend module, is needed to exploit this.