Publish Advisories

GHSA-7x6f-jvmg-6fgp
GHSA-hwrc-w5gg-f335
GHSA-7x6f-jvmg-6fgp
GHSA-hwrc-w5gg-f335
This commit is contained in:
advisory-database[bot]
2025-04-10 12:22:45 +00:00
parent bf498332c2
commit 49e6f998ed
4 changed files with 203 additions and 94 deletions
@@ -0,0 +1,69 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7x6f-jvmg-6fgp",
"modified": "2025-04-10T12:21:49Z",
"published": "2022-05-02T03:52:19Z",
"aliases": [
"CVE-2009-4159"
],
"summary": "TYPO3 Direct Mail Extension Vulnerable to Cross-Site Scripting (XSS)",
"details": "Cross-site scripting (XSS) vulnerability in the newsletter configuration feature in the backend module in the Direct Mail (direct_mail) extension 2.6.4 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "directmailteam/direct-mail"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.6.5"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2009-4159"
},
{
"type": "PACKAGE",
"url": "https://github.com/kartolo/direct_mail"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20110108051351/http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-018"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20200228220911/http://www.securityfocus.com/bid/37166"
},
{
"type": "WEB",
"url": "http://typo3.org/extensions/repository/view/direct_mail/2.6.5"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2025-04-10T12:21:48Z",
"nvd_published_at": "2009-12-02T17:30:00Z"
}
}
@@ -0,0 +1,134 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwrc-w5gg-f335",
"modified": "2025-04-10T12:20:56Z",
"published": "2022-05-02T03:47:10Z",
"aliases": [
"CVE-2009-3635"
],
"summary": "TYPO3 Install Tool Subcomponent Allows Access Using Only a Password's MD5 Hash as a Credential",
"details": "The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to gain access by using only the password's md5 hash as a credential.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.0.13"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.1.0"
},
{
"fixed": "4.1.13"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.2.0"
},
{
"fixed": "4.2.10"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.3beta1"
},
{
"fixed": "4.3beta2"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3635"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53928"
},
{
"type": "PACKAGE",
"url": "https://github.com/TYPO3/typo3"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20100105023145/http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20200229210314/http://www.securityfocus.com/bid/36801"
},
{
"type": "WEB",
"url": "http://marc.info/?l=oss-security&m=125632856206736&w=2"
},
{
"type": "WEB",
"url": "http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-04-10T12:20:56Z",
"nvd_published_at": "2009-11-02T15:30:00Z"
}
}
@@ -1,43 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7x6f-jvmg-6fgp",
"modified": "2025-04-09T04:16:53Z",
"published": "2022-05-02T03:52:19Z",
"aliases": [
"CVE-2009-4159"
],
"details": "Cross-site scripting (XSS) vulnerability in the newsletter configuration feature in the backend module in the Direct Mail (direct_mail) extension 2.6.4 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2009-4159"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/37552"
},
{
"type": "WEB",
"url": "http://typo3.org/extensions/repository/view/direct_mail/2.6.5"
},
{
"type": "WEB",
"url": "http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-018"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/37166"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2009-12-02T17:30:00Z"
}
}
@@ -1,51 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwrc-w5gg-f335",
"modified": "2025-04-09T04:15:56Z",
"published": "2022-05-02T03:47:10Z",
"aliases": [
"CVE-2009-3635"
],
"details": "The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to gain access by using only the password's md5 hash as a credential.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3635"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53928"
},
{
"type": "WEB",
"url": "http://marc.info/?l=oss-security&m=125632856206736&w=2"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/37122"
},
{
"type": "WEB",
"url": "http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/36801"
},
{
"type": "WEB",
"url": "http://www.vupen.com/english/advisories/2009/3009"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2009-11-02T15:30:00Z"
}
}