Количество 2
Количество 2
CVE-2026-8727
The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl via a Scheduler task.
GHSA-jr8m-x4p7-p3v5
TYPO3 Remote Code Execution in extension "Site Crawler" (crawler)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-8727 The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl via a Scheduler task. | 0% Низкий | 3 месяца назад | ||
GHSA-jr8m-x4p7-p3v5 TYPO3 Remote Code Execution in extension "Site Crawler" (crawler) | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу