Логотип exploitDog
bind:CVE-2022-31046
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-31046

Количество 2

Количество 2

nvd логотип

CVE-2022-31046

больше 3 лет назад

TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, the export functionality fails to limit the result set to allowed columns of a particular database table. This way, authenticated users can export internal details of database tables they already have access to. TYPO3 versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, 11.5.11 fix the problem described above. In order to address this issue, access to mentioned export functionality is completely denied for regular backend users.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8gmv-9hwg-w89g

больше 3 лет назад

Information Disclosure via Export Module

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-31046

TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, the export functionality fails to limit the result set to allowed columns of a particular database table. This way, authenticated users can export internal details of database tables they already have access to. TYPO3 versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, 11.5.11 fix the problem described above. In order to address this issue, access to mentioned export functionality is completely denied for regular backend users.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-8gmv-9hwg-w89g

Information Disclosure via Export Module

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу