Description
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend user account, with access to the Direct Mail Configuration backend module, is needed to exploit this.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Code Execution
Action: Apply Patch
AI Analysis

Impact

An authenticated backend user can write to an arbitrary TSConfig page for folders configured as Direct Mail in the Direct Mail extension. This flaw (CWE‑863) enables configuration injection in TYPO3 10.4 and later, and for TYPO3 9.5 and earlier it can further lead to arbitrary code execution. The attacker can cause the TYPO3 installation to run arbitrary PHP code, potentially compromising the server and all data managed by the site.

Affected Systems

The Direct Mail extension (direct_mail) for TYPO3 up to version 9.5.1 is affected. Sites running TYPO3 9.5 or older with this extension can be exploited for arbitrary code execution, while installations using TYPO3 10.4 or newer that still deploy the vulnerable extension risk configuration injection. Any TYPO3 installation with the Direct Mail backend configuration module exposed is relevant.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and the EPSS score of less than 1% suggests a low predicted exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The attack requires a valid backend account with access to the Direct Mail configuration module; limiting that access and monitoring backend activity can mitigate the threat.

Generated by OpenCVE AI on September 15, 2026 at 17:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Direct Mail extension to a fixed version beyond 9.5.1.
  • If an update is not available, uninstall or disable the Direct Mail extension to remove the vulnerability.
  • Restrict backend user permissions for the Direct Mail configuration module so that only trusted administrators can modify TSConfig settings and monitor backend logs for unauthorized changes.

Generated by OpenCVE AI on September 15, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p6xx-fhfw-7mj7 Configuration Injection in extension "Direct Mail" (direct_mail)
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Typo3
Typo3 direct Mail
Vendors & Products Typo3
Typo3 direct Mail

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Authenticated Backend Configuration Injection in TYPO3 Direct Mail Leading to Arbitrary Code Execution

Mon, 14 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Direct Mail Extension Configuration Injection Leading to Arbitrary Code Execution in TYPO3

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Direct Mail Extension Configuration Injection Leading to Arbitrary Code Execution in TYPO3

Mon, 14 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend user account, with access to the Direct Mail Configuration backend module, is needed to exploit this.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Typo3 Direct Mail
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:12:30.987Z

Reserved: 2023-12-10T00:00:00.000Z

Link: CVE-2023-50461

cve-icon Vulnrichment

Updated: 2026-09-14T16:12:26.075Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:15.653

Modified: 2026-09-22T20:00:03.713

Link: CVE-2023-50461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:46:55Z

Weaknesses