CVE-2014-3947: Code Injection
Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with a crafted extension, then accessing it via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3947?
CVE-2014-3947 is considered to have a critical severity due to its ability to allow remote code execution.
How do I fix CVE-2014-3947?
To fix CVE-2014-3947, update the powermail extension to version 1.6.11 or 2.0.14 or later.
What systems are affected by CVE-2014-3947?
CVE-2014-3947 affects powermail versions before 1.6.11 and 2.x versions before 2.0.14.
How does CVE-2014-3947 exploit occur?
CVE-2014-3947 exploits an unrestricted file upload vulnerability, allowing attackers to upload malicious files.
Can I mitigate CVE-2014-3947 without updating?
While updating is the best method, additional security measures like file type validation may help mitigate CVE-2014-3947.