{"id":"GHSA-j2w4-45qm-r674","summary":"direct_mail for Typo3 sensitive data exposure","details":"The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users table) to view and export data of frontend users who are subscribed to a newsletter.","aliases":["CVE-2019-16698"],"modified":"2024-02-22T05:31:01.593686Z","published":"2022-05-24T16:58:55Z","database_specific":{"github_reviewed_at":"2023-07-18T18:52:44Z","nvd_published_at":"2019-10-16T19:15:00Z","cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16698"},{"type":"WEB","url":"https://github.com/kartolo/direct_mail/commit/3a70924777294c7fb40e9f6eb3f7627bac58dfd1"},{"type":"WEB","url":"https://extensions.typo3.org/extension/direct_mail"},{"type":"PACKAGE","url":"https://github.com/kartolo/direct_mail"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2019-016"}],"affected":[{"package":{"name":"directmailteam/direct-mail","ecosystem":"Packagist","purl":"pkg:composer/directmailteam/direct-mail"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.3"}]}],"versions":["5.0","5.0.1","5.1.0","5.2.0","5.2.1","5.2.2","v5.1.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 5.2.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j2w4-45qm-r674/GHSA-j2w4-45qm-r674.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}