Логотип exploitDog
bind:CVE-2024-34358
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-34358

Количество 2

Количество 2

nvd логотип

CVE-2024-34358

больше 1 года назад

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature on the `frame` HTTP query parameter (e.g. `/index.php?eID=tx_cms_showpic?file=3&...&frame=12345`). This allows adversaries to instruct the system to produce an arbitrary number of thumbnail images on the server side. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36g8-62qv-5957

больше 1 года назад

TYPO3 vulnerable to an Uncontrolled Resource Consumption in the ShowImageController

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-34358

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature on the `frame` HTTP query parameter (e.g. `/index.php?eID=tx_cms_showpic?file=3&...&frame=12345`). This allows adversaries to instruct the system to produce an arbitrary number of thumbnail images on the server side. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-36g8-62qv-5957

TYPO3 vulnerable to an Uncontrolled Resource Consumption in the ShowImageController

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу