First published: Wed May 13 2020(Updated: )
The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dkd Direct Mail | <=5.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12699 is a vulnerability in the direct_mail extension for TYPO3 that allows for an Open Redirect via jumpUrl.
CVE-2020-12699 has a severity rating of medium with a CVSS score of 6.1.
CVE-2020-12699 allows an attacker to redirect users to a potentially malicious website through the jumpUrl parameter in the direct_mail extension.
The direct_mail extension up to and including version 5.2.3 is affected by CVE-2020-12699.
To mitigate CVE-2020-12699, it is recommended to update the direct_mail extension to a version that includes a fix for the vulnerability.