Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77p4-wfr8-977w

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

TYPO3 Directory Traversal on ZIP extraction

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.)

Пакеты

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.2.2

10.2.2

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 8.0.0, < 8.7.30

8.7.30

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 9.0.0, < 9.5.12

9.5.12

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.2.2

10.2.2

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 8.0.0, < 8.7.30

8.7.30

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 9.0.0, < 9.5.12

9.5.12

EPSS

Процентиль: 60%
0.00394
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.2
nvd
около 6 лет назад

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.)

EPSS

Процентиль: 60%
0.00394
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-22