Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-50461

Quick assessment

Affected
TYPO3 direct_mail
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在TYPO3的direct_mail(又名 Direct Mail)扩展(版本至9.5.1)中发现了一个问题。该扩展的配置后端模块允许已认证的用户向配置为 Direct Mail 的文件夹的任意 TSConfig 页面进行写入。利用此漏洞可能导致配置注入(Configuration Injection,适用于 TYPO3 10.4 及以上版本),并在 TYPO3 9.5 及以下版本中可能导致任意代码执行(Arbitrary Code Execution)。利用该漏洞需要一个有效的后端用户账户,且该账户需拥有访问 D

CVSS 8.8 · High EPSS 1.52% · P82

Possible ATT&CK Techniques 1 AI

T1553.004 · Install Root Certificate
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-50461

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend user account, with access to the Direct Mail Configuration backend module, is needed to exploit this.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TYPO3 direct_mail 0 ~ 6.0.3 -

II. Public POCs for CVE-2023-50461

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-50461

登录查看更多情报信息。

Vendor Advisories for CVE-2023-50461 (1)

Same Patch Batch · TYPO3 · 2026-09-14 · 5 CVEs total

CVE-2023-50460 5.4 MEDIUM TYPO3 femanager 7.x 授权用户操作任意前端用户
CVE-2023-50459 5.4 MEDIUM TYPO3 femanager 7.x<7.2.3 前端用户权限检查缺失
CVE-2023-50462 5.3 MEDIUM TYPO3 content_consent 2.0.1 IDOR 漏洞
CVE-2023-45023 4.2 MEDIUM TYPO3 femanager 7<7.2.2 邀请功能访问控制漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2023-50461

No comments yet


Leave a comment