Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6c46-p6j5-3f49

Опубликовано: 13 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

TYPO3 CMS Allows Broken Access Control in Redirects Module

Problem

Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect record - without restriction to the user’s own file‑mounts or web‑mounts. This allowed attackers to insert or alter redirects pointing to arbitrary URLs - facilitating phishing or other malicious redirect attacks.

Solution

Update to TYPO3 versions 10.4.55 ELTS, 11.5.49 ELTS, 12.4.41 LTS, 13.4.23 LTS, 14.0.2 that fix the problem described.

Credits

Thanks to Georg Dümmler for reporting this issue, and to TYPO3 security team member Elias Häußler for fixing it.

References

Пакеты

Наименование

typo3/cms-redirects

composer
Затронутые версииВерсия исправления

>= 14.0.0, <= 14.0.1

14.0.2

Наименование

typo3/cms-redirects

composer
Затронутые версииВерсия исправления

>= 13.0.0, <= 13.4.22

13.4.23

Наименование

typo3/cms-redirects

composer
Затронутые версииВерсия исправления

>= 12.0.0, <= 12.4.40

12.4.41

Наименование

typo3/cms-redirects

composer
Затронутые версииВерсия исправления

>= 11.0.0, <= 11.5.48

11.5.49

Наименование

typo3/cms-redirects

composer
Затронутые версииВерсия исправления

>= 10.0.0, <= 10.4.54

10.4.55

EPSS

Процентиль: 1%
0.00009
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.4
nvd
25 дней назад

Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect record without restriction to the user’s own file-mounts or web-mounts. This allowed attackers to insert or alter redirects pointing to arbitrary URLs – facilitating phishing or other malicious redirect attacks. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22 and 14.0.0-14.0.1.

EPSS

Процентиль: 1%
0.00009
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862