{"id":"CVE-2022-47408","aliases":["GHSA-f683-35w9-28g5"],"url":"https://o3.security/vulnerability/CVE-2022-47408","summary":"Multiple vulnerabilities in extension \"Newsletter subscriber management\" (fp_newsletter)","details":"The CAPTCHA of the extension can be bypassed which may result in automated creation of various newsletter subscribers. It is possible to provide arbitrary subscription UIDs to the `deleteAction` of the extension resulting in all newsletter subscribers to be unsubscribed. Insufficient access checks in the `createAction` and `unsubscribeAction` can be used to obtain data of existing newsletter subscribers.","published":"2022-12-14T00:00:00Z","modified":"2026-08-27T03:51:48.583537022Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AC:L/AV:N/A:N/C:H/I:H/PR:N/S:U/UI:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"fixpunkt/fp-newsletter","fixedVersion":"3.2.6"},{"ecosystem":"Packagist","name":"fixpunkt/fp-newsletter","fixedVersion":"2.1.2"},{"ecosystem":"Packagist","name":"fixpunkt/fp-newsletter","fixedVersion":"1.1.1"}],"fix":{"url":"https://github.com/bihor/fp_newsletter/commit/bc673cd9ab04f3fdd1225303f2ccb378b11a3747","label":"bihor/fp_newsletter@bc673cd"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/47xxx/CVE-2022-47408.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-47408"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-ext-sa-2022-017"},{"type":"WEB","url":"https://github.com/bihor/fp_newsletter/commit/bc673cd9ab04f3fdd1225303f2ccb378b11a3747"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/fixpunkt/fp-newsletter/CVE-2022-47408.yaml"},{"type":"PACKAGE","url":"https://github.com/bihor/fp_newsletter"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:51:48.583537022Z"}}