CVE-2022-47411

An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fp_newsletter_project:fp_newsletter:*:*:*:*:*:typo3:*:*
cpe:2.3:a:fp_newsletter_project:fp_newsletter:*:*:*:*:*:typo3:*:*
cpe:2.3:a:fp_newsletter_project:fp_newsletter:*:*:*:*:*:typo3:*:*
cpe:2.3:a:fp_newsletter_project:fp_newsletter:*:*:*:*:*:typo3:*:*
cpe:2.3:a:fp_newsletter_project:fp_newsletter:1.2.0:*:*:*:*:typo3:*:*

History

21 Apr 2025, 19:15

Type Values Removed Values Added
CWE CWE-200

21 Nov 2024, 07:31

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.1
References () https://typo3.org/security/advisory/typo3-ext-sa-2022-017 - Patch, Vendor Advisory () https://typo3.org/security/advisory/typo3-ext-sa-2022-017 - Patch, Vendor Advisory

Information

Published : 2022-12-14 21:15

Updated : 2025-04-21 19:15


NVD link : CVE-2022-47411

Mitre link : CVE-2022-47411

CVE.ORG link : CVE-2022-47411


JSON object : View

Products Affected

fp_newsletter_project

  • fp_newsletter
CWE
NVD-CWE-Other CWE-200

Exposure of Sensitive Information to an Unauthorized Actor