Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54jj-pxx2-pv8h

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

TYPO3 doesn't properly check file extensions

The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.

Пакеты

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.0.8

6.0.8

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 6.1.0, < 6.1.3

6.1.3

EPSS

Процентиль: 60%
0.00391
Низкий

8.7 High

CVSS4

Дефекты

CWE-20
CWE-434

Связанные уязвимости

ubuntu
больше 11 лет назад

The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.

nvd
больше 11 лет назад

The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.

debian
больше 11 лет назад

The (1) file upload component and (2) File Abstraction Layer (FAL) in ...

EPSS

Процентиль: 60%
0.00391
Низкий

8.7 High

CVSS4

Дефекты

CWE-20
CWE-434