CVE-2022-47410

CRITICAL

fp_newsletter < 1.1.1, 1.2.0, 2.x < 2.1.2, 2.2.1-2.4.0, 3.x < 3.2.6 - Subscriber Data Exposure

Title source: llm
STIX 2.1

Description

An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations.

References (1)

Core 1
Core References

Scores

CVSS v3 9.1
EPSS 0.0067
EPSS Percentile 47.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-200
Status published
Products (3)
fixpunkt/fp-newsletter 0 - 1.1.1Packagist
fp_newsletter_project/fp_newsletter 1.2.0
fp_newsletter_project/fp_newsletter < 1.1.1
Published Dec 14, 2022
Tracked Since Feb 18, 2026