VYPR
Moderate severityNVD Advisory· Published May 13, 2020· Updated Aug 4, 2024

CVE-2020-12699

CVE-2020-12699

Description

The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Open redirect vulnerability in TYPO3 Direct Mail extension through 5.2.3 allows attackers to redirect users to arbitrary URLs via a crafted jumpUrl parameter.

Description

The Direct Mail extension for TYPO3 (ext:direct_mail) through version 5.2.3 contains an open redirect vulnerability (CVE-2020-12699) due to improper handling of the “jumpUrl” functionality. This flaw allows an attacker to craft a link that, when clicked by a user, redirects them to an arbitrary external URL. The open redirect is part of a set of vulnerabilities discovered in the extension, as detailed in the TYPO3 security advisory [3].

Exploitation

Exploitation requires no authentication; an attacker can embed a malicious jumpUrl link in a newsletter or other communication sent via the extension. The victim only needs to click on the link for the redirection to occur. Since the extension is often used for mass mailings, a single malicious link can reach many recipients, increasing the attack surface [2].

Impact

Successful exploitation enables an attacker to redirect users to phishing sites, malware downloads, or other malicious destinations, potentially leading to credential theft or further compromise. The open redirect can also be used to bypass security controls that rely on domain validation [3].

Mitigation

The vulnerability is fixed in version 5.2.4 of the Direct Mail extension. Users are strongly advised to update immediately via the TYPO3 extension manager or by downloading the update from the TYPO3 Extension Repository [3]. No workarounds are available.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
directmailteam/direct-mailPackagist
< 5.2.45.2.4

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.