Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2wj9-434x-9hvp

Опубликовано: 13 мая 2020
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Insecure Deserialization in Backend User Settings in TYPO3 CMS

It has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of 3rd party components this can lead to remote code execution. A valid backend user account is needed to exploit this vulnerability.

Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.

References

Пакеты

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 9.0.0, < 9.5.17

9.5.17

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.4.2

10.4.2

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.4.2

10.4.2

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 9.0.0, < 9.5.17

9.5.17

EPSS

Процентиль: 78%
0.01181
Низкий

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of third party components, this can lead to remote code execution. A valid backend user account is needed to exploit this vulnerability. This has been fixed in 9.5.17 and 10.4.2.

EPSS

Процентиль: 78%
0.01181
Низкий

8.8 High

CVSS3

Дефекты

CWE-502