CVE-2024-45233 is a critical Broken Access Control vulnerability affecting the powermail extension (versions through 12.3.5) for TYPO3, specifically when Powermail Frontend plugins are in use. This flaw allows unauthenticated attackers to edit, update, delete, or export data from persisted forms due to missing or insufficient access checks in the OutputController. With a CVSS score of 9.8 (Critical), it presents a high risk of complete compromise of confidentiality, integrity, and availability. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and while there's limited community discussion, there is no indication of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.5.0CPE matchmatch criteria | cpe:2.3:a:in2code:powermail:*:*:*:*:*:typo3:*:* | ||
>= 8.0.0, < 8.5.0CPE matchmatch criteria | cpe:2.3:a:in2code:powermail:*:*:*:*:*:typo3:*:* | ||
>= 9.0.0, < 10.9.0CPE matchmatch criteria | cpe:2.3:a:in2code:powermail:*:*:*:*:*:typo3:*:* | ||
>= 12.0.0, < 12.4.0CPE matchmatch criteria | cpe:2.3:a:in2code:powermail:*:*:*:*:*:typo3:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.