Direct Mail
Vendor:
First CVE: Dec 29, 2017 · Active for 8 years
6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 10% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Direct Mail over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 29, 2017
8 years ago
Most Recent CVE
May 13, 2020
2,263 days ago
CVE Severity & Scoring
Direct Mail6 CVEs
83%
17%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low3 (50.0%)
High0 (0.0%)
None3 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7400HIGH The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checking of authentication codes. | Dec 29, 2017 | 7.5 | 25 | NO | NO |
CVE-2020-12699MEDIUM The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl. | May 13, 2020 | 6.1 | 20 | NO | NO |
CVE-2020-12700MEDIUM The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special Query. | May 13, 2020 | 4.3 | 17 | NO | NO |
CVE-2020-12697MEDIUM The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries. | May 13, 2020 | 5.3 | 16 | NO | NO |
CVE-2019-16698MEDIUM The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users t | Oct 16, 2019 | 4.3 | 16 | NO | NO |
CVE-2020-12698MEDIUM The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber tables. | May 13, 2020 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Direct Mail
Top CWEs
Versions
No cataloged versions.