Project

General

Profile

Actions

Bug #21336

closed

Encryption key can be recalculated when using normal mailform when [FE][strictFormmail] == 0

Added by Ernesto Baschny over 14 years ago. Updated almost 14 years ago.

Status:
Closed
Priority:
Must have
Category:
-
Target version:
-
Start date:
2009-10-22
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
4.3
PHP Version:
5.2
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

These settings required for being exploitable:
['TYPO3_CONF_VARS']['FE']['secureFormmail'] 0
['TYPO3_CONF_VARS']['FE']['strictFormmail'] 0

Reported by Stefan Schuler.

Security Team OTRS reference: 2009021010000086
(issue imported from #M12310)

Actions

Also available in: Atom PDF