PT-2014-5627 · Typo3 · Typo3 Powermail Extension

Wouter Van Dongen

·

Published

2014-10-03

·

Updated

2022-05-17

·

CVE-2014-3947

CVSS v4.0

8.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions TYPO3 powermail extension versions prior to 1.6.11 TYPO3 powermail extension versions 2.x prior to 2.0.14
Description The issue allows remote attackers to execute arbitrary code by uploading a file with a crafted extension. This can be achieved by accessing the uploaded file via unspecified vectors.
Recommendations For versions prior to 1.6.11, update to version 1.6.11 or later. For versions 2.x prior to 2.0.14, update to version 2.0.14 or later.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3947
GHSA-M278-C6GG-4JRR

Affected Products

Typo3 Powermail Extension