PT-2007-2509 · Typo3 · Typo3
Published
2007-02-22
·
Updated
2017-07-29
·
CVE-2007-1081
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
TYPO3 versions prior to 4.0.5
TYPO3 versions 4.1beta
TYPO3 versions 4.1RC1
Description
The issue allows attackers to inject arbitrary email headers via unknown vectors in the start function in class.t3lib formmail.php.
Recommendations
For versions prior to 4.0.5, update to version 4.0.5 or later.
For versions 4.1beta and 4.1RC1, avoid using the start function in class.t3lib formmail.php until a patch is available.
As a temporary workaround, consider restricting access to the email functionality to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Typo3