High severity7.5NVD Advisory· Published Dec 29, 2017· Updated May 13, 2026
CVE-2013-7400
CVE-2013-7400
Description
The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checking of authentication codes.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
directmailteam/direct-mailPackagist | < 3.1.2 | 3.1.2 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- extensions.typo3.org/extension/direct_mail/nvdProductRelease NotesVendor Advisory
- github.com/advisories/GHSA-4mh5-jj5w-3f9qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-7400ghsaADVISORY
- typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-014/nvdVendor Advisory
- www.openwall.com/lists/oss-security/2014/09/11/4nvdIssue TrackingMailing ListWEB
- extensions.typo3.org/extension/direct_mailghsaWEB
- typo3.org/security/advisory/typo3-ext-sa-2013-014ghsaWEB
News mentions
0No linked articles in our index yet.