Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p6xx-fhfw-7mj7 | Configuration Injection in extension "Direct Mail" (direct_mail) |
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2023-011 |
|
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typo3
Typo3 direct Mail |
|
| Vendors & Products |
Typo3
Typo3 direct Mail |
Tue, 15 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Backend Configuration Injection in TYPO3 Direct Mail Leading to Arbitrary Code Execution |
Mon, 14 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Direct Mail Extension Configuration Injection Leading to Arbitrary Code Execution in TYPO3 |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Direct Mail Extension Configuration Injection Leading to Arbitrary Code Execution in TYPO3 |
Mon, 14 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend user account, with access to the Direct Mail Configuration backend module, is needed to exploit this. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-14T16:12:30.987Z
Reserved: 2023-12-10T00:00:00.000Z
Link: CVE-2023-50461
Updated: 2026-09-14T16:12:26.075Z
Status : Received
Published: 2026-09-14T07:17:15.653
Modified: 2026-09-14T17:17:42.147
Link: CVE-2023-50461
No data.
OpenCVE Enrichment
Updated: 2026-09-17T19:46:55Z
Github GHSA