Impact
An authenticated backend user can write to an arbitrary TSConfig page for folders configured as Direct Mail in the Direct Mail extension. This flaw (CWE‑863) enables configuration injection in TYPO3 10.4 and later, and for TYPO3 9.5 and earlier it can further lead to arbitrary code execution. The attacker can cause the TYPO3 installation to run arbitrary PHP code, potentially compromising the server and all data managed by the site.
Affected Systems
The Direct Mail extension (direct_mail) for TYPO3 up to version 9.5.1 is affected. Sites running TYPO3 9.5 or older with this extension can be exploited for arbitrary code execution, while installations using TYPO3 10.4 or newer that still deploy the vulnerable extension risk configuration injection. Any TYPO3 installation with the Direct Mail backend configuration module exposed is relevant.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of less than 1% suggests a low predicted exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The attack requires a valid backend account with access to the Direct Mail configuration module; limiting that access and monitoring backend activity can mitigate the threat.
OpenCVE Enrichment
Github GHSA