Powermail for TYPO3 SQL Injection and Cross Site Scripting Vulnerabilities
Description
Multiple vulnerabilities have been identified in Powermail extension for TYPO3, which could be exploited by attackers to disclose sensitive information or inject SQL queries. These issues are caused by input validation errors when processing user-supplied parameters and data, which could be exploited to conduct SQL injection or cross site scripting attacks, or inject abritrary values into validated fields like "Email" or "URL".
Vulnerable Products
Vulnerable Software: Powermail extension for TYPO3 version 1.5.3 and prior