CVE-2024-45232

MEDIUM

powermail <12.3.5 - IDOR

Title source: llm
STIX 2.1

Description

An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting in Insecure Direct Object Reference (IDOR). An unauthenticated attacker can use this to display the user-submitted data of all forms persisted by the extension. This can only be exploited when the extension is configured to save submitted form data to the database (plugin.tx_powermail.settings.db.enable=1), which however is the default setting of the extension. The fixed versions are 7.5.0, 8.5.0, 10.9.0, and 12.4.0

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0022
EPSS Percentile 44.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
in2code/powermail < 7.5.0
in2code/powermail 11.0.0 - 12.4.0Packagist
Published Aug 29, 2024
Tracked Since Feb 18, 2026