CVE-2023-50461
moderateAuthorization Flaw in TYPO3 direct_mail Extension Enables Config Injection/RCE
The direct_mail (Direct Mail) extension for TYPO3, through version 9.5.1, contains an authorization flaw (CWE-863) in its Configuration backend module that allows an authenticated backend user with access to that module to write to the TSConfig of an arbitrary page, not just the Direct Mail folders they should be able to manage. The flaw is triggered simply by saving configuration through the module while targeting an arbitrary page, bypassing the intended restriction. Impact depends on the TYPO3 core version: on TYPO3 10.4 and above, this yields configuration injection, while on TYPO3 9.5 and below it can escalate to arbitrary code execution, which is why the issue carries a high CVSS 3.1 score of 8.8. Affected installations are TYPO3 sites running direct_mail 9.5.1 or earlier where backend users — including low-privileged accounts — have been granted access to the Direct Mail Configuration module. No public proof-of-concept is known, the CVE is not on CISA's KEV list, and no exploitation in the wild has been reported.
What to do: Upgrade the direct_mail extension to a release newer than 9.5.1 (the latest available version) as soon as possible. Restrict backend user/group access to the Direct Mail Configuration module to only those who genuinely need it, since exploitation requires such access, and audit pages' TSConfig records for unauthorized modifications. Prioritize remediation on sites still running TYPO3 9.5 or below, which is itself end-of-life, because there the flaw can lead to arbitrary code execution.
| Direct Mail Team (TYPO3 extension) direct_mail (Direct Mail) extension for TYPO3 | All versions through 9.5.1 (≤9.5.1) |
| TYPO3 CMS (platform context when combined with direct_mail ≤9.5.1) | TYPO3 9.5 and below (flaw escalates to arbitrary code execution); TYPO3 10.4 and above (flaw yields configuration injection) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend user account, with access to the Direct Mail Configuration backend module, is needed to exploit this.
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.