CVE-2023-50461
Received
Received - Intake
Direct Mail Configuration Injection in TYPO3
Vulnerability report for CVE-2023-50461, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-14
Last updated on: 2026-09-14
Assigner: MITRE
Description
Description
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend user account, with access to the Direct Mail Configuration backend module, is needed to exploit this.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| typo3 | direct_mail | 6.0.2 |
| typo3 | direct_mail | to 6.0.3 (exc) |
| typo3 | direct_mail | 7.0.0 |
| typo3 | direct_mail | From 7.0.0 (inc) to 7.0.2 (inc) |
| typo3 | direct_mail | 8.0.0 |
| typo3 | direct_mail | 9.5.1 |
| typo3 | direct_mail | From 9.5.2 (inc) |
| typo3 | direct_mail | From 10.4 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |