CVE-2019-16698: Dkd Direct Mail

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users table) to view and export data of frontend users who are subscribed to a newsletter.

Affected products

  • Dkd Direct Mail: up to and including 5.2.2

Published 2019-10-16. Last modified 2026-06-17.