Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pm6-9fhx-vvg3

Опубликовано: 18 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.2
CVSS3: 8.8

Описание

The mailqueue TYPO3 extension has Insecure Deserialization in TransportFailure class

Description

The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'].

Пакеты

Наименование

cpsit/typo3-mailqueue

composer
Затронутые версииВерсия исправления

< 0.4.5

0.4.5

Наименование

cpsit/typo3-mailqueue

composer
Затронутые версииВерсия исправления

>= 0.5.0, < 0.5.2

0.5.2

EPSS

Процентиль: 12%
0.00215
Низкий

5.2 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
nvd
5 месяцев назад

The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'].

EPSS

Процентиль: 12%
0.00215
Низкий

5.2 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-502