Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-55g3-fjwm-w2c8

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

TYPO3 Color Picker Wizard component allows remote authenticated editors to execute arbitrary PHP code

The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authenticated editors to execute arbitrary PHP code via a serialized PHP object.

Пакеты

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 4.5.0, < 4.5.34

4.5.34

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 4.7.0, < 4.7.19

4.7.19

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.0.14

6.0.14

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 6.1.0, < 6.1.9

6.1.9

EPSS

Процентиль: 74%
0.01634
Низкий

8.7 High

CVSS4

Дефекты

CWE-94

Связанные уязвимости

ubuntu
около 12 лет назад

The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authenticated editors to execute arbitrary PHP code via a serialized PHP object.

nvd
около 12 лет назад

The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authenticated editors to execute arbitrary PHP code via a serialized PHP object.

debian
около 12 лет назад

The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 ...

EPSS

Процентиль: 74%
0.01634
Низкий

8.7 High

CVSS4

Дефекты

CWE-94