CVE-2022-47410

An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fp_newsletter_project:fp_newsletter:*:*:*:*:*:typo3:*:*
cpe:2.3:a:fp_newsletter_project:fp_newsletter:*:*:*:*:*:typo3:*:*
cpe:2.3:a:fp_newsletter_project:fp_newsletter:*:*:*:*:*:typo3:*:*
cpe:2.3:a:fp_newsletter_project:fp_newsletter:*:*:*:*:*:typo3:*:*
cpe:2.3:a:fp_newsletter_project:fp_newsletter:1.2.0:*:*:*:*:typo3:*:*

History

21 Apr 2025, 19:15

Type Values Removed Values Added
CWE CWE-200

21 Nov 2024, 07:31

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.1
References () https://typo3.org/security/advisory/typo3-ext-sa-2022-017 - Patch, Vendor Advisory () https://typo3.org/security/advisory/typo3-ext-sa-2022-017 - Patch, Vendor Advisory

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-668 NVD-CWE-Other

Information

Published : 2022-12-14 21:15

Updated : 2025-04-21 19:15


NVD link : CVE-2022-47410

Mitre link : CVE-2022-47410

CVE.ORG link : CVE-2022-47410


JSON object : View

Products Affected

fp_newsletter_project

  • fp_newsletter
CWE
NVD-CWE-Other CWE-200

Exposure of Sensitive Information to an Unauthorized Actor