The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checking of authentication codes.
{
"cwe_ids": [
"CWE-200"
],
"github_reviewed": true,
"github_reviewed_at": "2025-04-21T16:18:22Z",
"nvd_published_at": "2017-12-29T15:29:00Z",
"severity": "HIGH"
}