Описание
yag and pt_extbase extensions for TYPO3 allow remote attackers to bypass access restrictions
The Ajax dispatcher for Extbase in the Yet Another Gallery (yag) extension before 3.0.1 and Tools for Extbase development (pt_extbase) extension before 1.5.1 allows remote attackers to bypass access restrictions and execute arbitrary controller actions via unspecified vectors.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-6289
- https://github.com/YAG-Gallery/yag/commit/4ab6ca121044d31b3822ab0c922053a9de8ee4ef
- https://github.com/punktDe/pt_extbase/commit/9969635830fcf5c3222de0fd9dc0d9a05f8d6cb1
- https://typo3.org/security/advisory/typo3-ext-sa-2014-005
- http://typo3.org/extensions/repository/view/pt_extbase
- http://typo3.org/extensions/repository/view/yag
Пакеты
Наименование
dl/yag
composer
Затронутые версииВерсия исправления
< 3.0.1
3.0.1
Наименование
punktde/pt_extbase
composer
Затронутые версииВерсия исправления
< 1.5.1
1.5.1
Связанные уязвимости
nvd
больше 11 лет назад
The Ajax dispatcher for Extbase in the Yet Another Gallery (yag) extension before 3.0.1 and Tools for Extbase development (pt_extbase) extension before 1.5.1 allows remote attackers to bypass access restrictions and execute arbitrary controller actions via unspecified vectors.