GHSA-mgw4-gv3f-g57j
Dashboard / Vulnerabilities / GHSA-mgw4-gv3f-g57j
Summary: TYPO3 powermail Extension Vulnerable to SQL Injection via Unspecified Vectors
Details: SQL injection vulnerability in the powermail extension 1.5.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to the "SQL selection field" and "typoscript."
References: https://nvd.nist.gov/vuln/detail/CVE-2010-0329, https://web.archive.org/web/20100123124044/http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021, http://typo3.org/extensions/repository/view/powermail/1.5.2, http://typo3.org/extensions/repository/view/powermail/1.5.2/info/changelog.txt
Affected packages
Package
Name: in2code/powermail
Purl: pkg:composer/in2code/powermail
Affected ranges
Type: ECOSYSTEM
Events:
