{"id":"CVE-2022-47409","details":"An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of modified subscription UIDs in deleteAction operations.","modified":"2026-04-02T08:26:42.484418Z","published":"2022-12-14T21:15:14.393Z","references":[{"type":"FIX","url":"https://typo3.org/security/advisory/typo3-ext-sa-2022-017"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bihor/fp_newsletter","events":[{"introduced":"0"},{"fixed":"f02062980922bdecdcc1daf8614ab92e63228378"},{"introduced":"0"},{"fixed":"ff8243ec42716418b79a45fb60200123a091cfc9"},{"introduced":"0"},{"fixed":"bc673cd9ab04f3fdd1225303f2ccb378b11a3747"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"1.1.1"},{"introduced":"2.0.0"},{"fixed":"2.1.2"},{"introduced":"3.0.0"},{"fixed":"3.2.6"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-47409.json","unresolved_ranges":[{"events":[{"introduced":"2.2.1"},{"last_affected":"2.4.0"}]},{"events":[{"introduced":"0"},{"last_affected":"1.2.0"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}