CVE-2009-4159
Description
Cross-site scripting (XSS) vulnerability in the newsletter configuration feature in the backend module in the Direct Mail (direct_mail) extension 2.6.4 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A cross-site scripting vulnerability in the Direct Mail TYPO3 extension (≤2.6.4) allows authenticated editors to inject arbitrary script via the newsletter configuration backend.
Vulnerability
The Direct Mail (direct_mail) extension for TYPO3 contains a persistent cross-site scripting (XSS) vulnerability in its backend newsletter configuration feature. The flaw exists in versions 2.6.4 and earlier; the extension does not properly sanitize user-supplied input, allowing the injection of arbitrary web script or HTML [1][3]. The vulnerable component is the backend module used by editors to administrate newsletter configurations [3].
Exploitation
An attacker must be an authenticated website editor with access to the Direct Mail backend module. By crafting specially crafted JavaScript or HTML in the newsletter configuration fields, the attacker can inject malicious code [3]. The injected script executes in the context of the backend module, potentially affecting other editors or administrators who view the configuration [1][3].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript or HTML in the backend of the TYPO3 installation. This can lead to session hijacking, defacement, or theft of sensitive data. Additionally, with specially crafted JavaScript, attackers may create malicious database records [3]. The impact is limited to authenticated users in the backend; however, it can escalate to broader compromise if administrative actions are performed by the victim.
Mitigation
The vulnerability is fixed in version 2.6.5, which is available from the TYPO3 extension manager and the TYPO3 extension repository [3][4]. Users of the Direct Mail extension are advised to update to 2.6.5 as soon as possible. No workaround is documented for unpatched installations. The extension is not part of the TYPO3 default installation [3].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
directmailteam/direct-mailPackagist | < 2.6.5 | 2.6.5 |
Affected products
14cpe:2.3:a:ivan_kartolo:direct_mail:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:ivan_kartolo:direct_mail:*:*:*:*:*:*:*:*range: <=2.6.4
- cpe:2.3:a:ivan_kartolo:direct_mail:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:ivan_kartolo:direct_mail:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:ivan_kartolo:direct_mail:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:ivan_kartolo:direct_mail:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:ivan_kartolo:direct_mail:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:ivan_kartolo:direct_mail:2.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:ivan_kartolo:direct_mail:2.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:ivan_kartolo:direct_mail:2.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:ivan_kartolo:direct_mail:2.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:ivan_kartolo:direct_mail:2.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:ivan_kartolo:direct_mail:2.6.3:*:*:*:*:*:*:*
- (no CPE)range: <=2.6.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- typo3.org/extensions/repository/view/direct_mail/2.6.5/nvdPatch
- typo3.org/teams/security/security-bulletins/typo3-sa-2009-018/nvdPatchVendor Advisory
- secunia.com/advisories/37552nvdVendor Advisory
- github.com/advisories/GHSA-7x6f-jvmg-6fgpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2009-4159ghsaADVISORY
- typo3.org/extensions/repository/view/direct_mail/2.6.5ghsaWEB
- web.archive.org/web/20110108051351/http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-018ghsaWEB
- web.archive.org/web/20200228220911/http://www.securityfocus.com/bid/37166ghsaWEB
- www.securityfocus.com/bid/37166nvd
News mentions
0No linked articles in our index yet.