CVE-2020-12698: Dkd Direct Mail

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber tables.

Affected products

  • Dkd Direct Mail: up to and including 5.2.3

Published 2020-05-13. Last modified 2026-06-17.