#VU27939 Allocation of Resources Without Limits or Throttling in Direct Mail - CVE-2020-12697
Published: May 15, 2020
Direct Mail
TYPO3
Description
The vulnerability allows a remote attacker to perofrm a denial of service (DoS) attack.
The vulnerability exists due to a functionality to log clicks on links in sent newsletters does not limit the amount of log entries generated per link. A remote attacker can use a valid link to fill the log table with a huge amount of records and cause a denial of service condition on the target system.