Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-11069

Опубликовано: 14 мая 2020
Источник: nvd
CVSS3: 8
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable to a same-site request forgery. A backend user can be tricked into interacting with a malicious resource an attacker previously managed to upload to the web server. Scripts are then executed with the privileges of the victims' user session. In a worst-case scenario, new admin users can be created which can directly be used by an attacker. The vulnerability is basically a cross-site request forgery (CSRF) triggered by a cross-site scripting vulnerability (XSS) - but happens on the same target host - thus, it's actually a same-site request forgery. Malicious payload such as HTML containing JavaScript might be provided by either an authenticated backend user or by a non-authenticated user using a third party extension, e.g. file upload in a contact form with knowing the target location. To be successful, the attacked victim requires an active

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.5.16 (включая)
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Версия от 10.0.0 (включая) до 10.4.1 (включая)

EPSS

Процентиль: 60%
0.00398
Низкий

8 High

CVSS3

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-346
NVD-CWE-Other

Связанные уязвимости

CVSS3: 8
github
больше 5 лет назад

Backend Same-Site Request Forgery in TYPO3 CMS

EPSS

Процентиль: 60%
0.00398
Низкий

8 High

CVSS3

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-346
NVD-CWE-Other