Home/Product/alex kellner powermail
Product

alex kellner powermail

13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-47047
<= 7.5.0
An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the create
7.5HIGH
CVE-2024-45233
< 7.5.0
An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be c
9.8CRITICAL
CVE-2024-45232
< 7.5.0
An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmati
5.3MEDIUM
CVE-2014-6288
all versions
The powermail extension 2.x before 2.0.11 for TYPO3 allows remote attackers to bypass the CAPTCHA protection mechanism via unspeci
CVE-2014-3947
<= 1.6.10
Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote atta
CVE-2014-3948
<= 1.6.10
Cross-site scripting (XSS) vulnerability in the HTML export wizard in the backend module in the powermail extension before 1.6.11
CVE-2012-5889
<= 1.6.4
Cross-site scripting (XSS) vulnerability in the powermail extension before 1.6.5 for TYPO3 allows remote attackers to inject arbit
CVE-2010-4892
<= 1.5.4
Cross-site scripting (XSS) vulnerability in the powermail extension before 1.5.5 for TYPO3 allows remote attackers to inject arbit
CVE-2010-3687
<= 1.5.3
Unspecified vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to bypass validation have
CVE-2010-3605
<= 1.5.2
Cross-site scripting (XSS) vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to inject
CVE-2010-3604
<= 1.5.2
SQL injection vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQ
CVE-2010-0329
<= 1.5.1
SQL injection vulnerability in the powermail extension 1.5.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQ
CVE-2008-2182
< 1.1.10
Cross-site scripting (XSS) vulnerability in the powermail extension before 1.1.10 for TYPO3 allows remote attackers to inject arbi