The CAPTCHA of the extension can be bypassed which may result in automated creation of various newsletter subscribers. It is possible to provide arbitrary subscription UIDs to the deleteAction
of the extension resulting in all newsletter subscribers to be unsubscribed. Insufficient access checks in the createAction
and unsubscribeAction
can be used to obtain data of existing newsletter subscribers.
{ "nvd_published_at": "2022-12-14T21:15:00Z", "cwe_ids": [ "CWE-863" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-02-08T00:23:48Z" }