SB2023010615 - Multiple vulnerabilities in Newsletter subscriber managment extension for TYPO3



SB2023010615 - Multiple vulnerabilities in Newsletter subscriber managment extension for TYPO3

Published: January 6, 2023

Security Bulletin ID SB2023010615
Severity
High
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 25% Medium 75%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 secuirty vulnerabilities.


1) Incorrect authorization (CVE-ID: CVE-2022-47408)

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to a CAPTCHA bypass. A remote attacker can cause subscribing many people.


2) Improper access control (CVE-ID: CVE-2022-47409)

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote attacker can unsubscribe everyone via a series of modified subscription UIDs in deleteAction operations.


3) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2022-47410)

The vulnerability allows a remote attacker to compromise the system.

The vulnerability exists due to exposure of resource to wrong sphere. A remote attacker can obtain subscribers via createAction operations.


4) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2022-47411)

The vulnerability allows a remote attacker to compromise the system.

The vulnerability exists due to exposure of resource to wrong sphere. A remote attacker can obtain subscribers via unsubscribeAction operations.


Remediation

Install update from vendor's website.