9.1
CVE-2022-47408
- EPSS 0.19%
- Veröffentlicht 14.12.2022 21:15:14
- Zuletzt bearbeitet 21.04.2025 19:15:18
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. There is a CAPTCHA bypass that can lead to subscribing many people.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fp Newsletter Project ≫ Fp Newsletter SwPlatformtypo3 Version < 1.1.1
Fp Newsletter Project ≫ Fp Newsletter SwPlatformtypo3 Version >= 2.0.0 < 2.1.2
Fp Newsletter Project ≫ Fp Newsletter SwPlatformtypo3 Version >= 2.2.1 <= 2.4.0
Fp Newsletter Project ≫ Fp Newsletter SwPlatformtypo3 Version >= 3.0.0 < 3.2.6
Fp Newsletter Project ≫ Fp Newsletter Version1.2.0 SwPlatformtypo3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.407 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| cve@mitre.org | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.