CVE-2010-3687: Medium severity in2code powermail vulnerability
Unspecified vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to bypass validation have an unspecified impact by "[injecting] arbitrary values into validated fields," as demonstrated using the (1) Email and (2) URL fields.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3687?
CVE-2010-3687 is categorized as a medium severity vulnerability due to its ability to bypass input validation.
How do I fix CVE-2010-3687?
To fix CVE-2010-3687, update the Powermail extension to version 1.5.4 or later.
What types of attacks can exploit CVE-2010-3687?
CVE-2010-3687 can be exploited by injecting arbitrary values into validated fields such as email and URL.
Which versions of Powermail are affected by CVE-2010-3687?
CVE-2010-3687 affects Powermail extensions up to version 1.5.3, including all earlier versions.
What impact does CVE-2010-3687 have on my TYPO3 installation?
The impact of CVE-2010-3687 includes potential data integrity issues due to unchecked inputs in forms.