Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3v8v-4wg6-r7qh

Опубликовано: 12 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.2

Описание

TYPO3 CMS: Destructive Actions on File Mount Folders

Problem

Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions.

Solution

Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.

Credits

TYPO3 CMS thanks Arne Uplegger for reporting this issue, and TYPO3 security team member Elias Häußler for fixing it.

Resources

Пакеты

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

< 10.4.57

10.4.57

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 11.0.0, < 11.5.51

11.5.51

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 12.0.0, < 12.4.46

12.4.46

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 13.0.0, < 13.4.31

13.4.31

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 14.0.0, < 14.3.3

14.3.3

EPSS

Процентиль: 15%
0.00238
Низкий

7.2 High

CVSS4

Дефекты

CWE-862

Связанные уязвимости

nvd
3 месяца назад

Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0 through 11.5.50, 12.0.0 through 12.4.45, 13.0.0 through 13.4.30, and 14.0.0 through 14.3.2.

EPSS

Процентиль: 15%
0.00238
Низкий

7.2 High

CVSS4

Дефекты

CWE-862