Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3p42-w5ch-gg42

Опубликовано: 12 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

Problem

Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out phishing attacks.

Solution

Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.

Credits

TYPO3 CMS thanks Alexandre Romao for reporting this issue, and TYPO3 core & security team member Benjamin Franzke for fixing it.

Resources

Пакеты

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

< 10.4.57

10.4.57

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 11.0.0, < 11.5.51

11.5.51

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 12.0.0, < 12.4.46

12.4.46

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 13.0.0, < 13.4.31

13.4.31

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 14.0.0, < 14.3.3

14.3.3

EPSS

Процентиль: 22%
0.00294
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-601

Связанные уязвимости

nvd
3 месяца назад

Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out phishing attacks. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

EPSS

Процентиль: 22%
0.00294
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-601