Typo3 · Newsletter Extension · CVE-2021-38302
Name of the Vulnerable Software and Affected Versions:
Newsletter extension versions through 4.0.0 for TYPO3
Description:
The issue allows SQL Injection when processing bounced emails. It has been discovered that the Newsletter extension is susceptible to this issue.
Recommendations:
For versions through 4.0.0, update to a version that contains a fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.