PT-2026-81236 · Typo3 · Powermail
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
TYPO3 Powermail (affected versions not specified)
Description
An issue exists where the extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as a template source without sanitization. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers, which may lead to the disclosure of server configuration, environment variables, and application source, and potentially result in remote code execution. This issue is reported to be actively exploited in the wild.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powermail