Логотип exploitDog
bind:CVE-2024-55892
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-55892

Количество 2

Количество 2

nvd логотип

CVE-2024-55892

8 месяцев назад

TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSRF attacks if the URL is used after passing the validation checks. Users are advised to update to TYPO3 versions 9.5.49 ELTS, 10.4.48 ELTS, 11.5.42 LTS, 12.4.25 LTS, 13.4.3 which fix the problem described. There are no known workarounds for this vulnerability.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2fx5-pggv-6jjr

8 месяцев назад

TYPO3 Potential Open Redirect via Parsing Differences

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-55892

TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSRF attacks if the URL is used after passing the validation checks. Users are advised to update to TYPO3 versions 9.5.49 ELTS, 10.4.48 ELTS, 11.5.42 LTS, 12.4.25 LTS, 13.4.3 which fix the problem described. There are no known workarounds for this vulnerability.

CVSS3: 4.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2fx5-pggv-6jjr

TYPO3 Potential Open Redirect via Parsing Differences

CVSS3: 4.8
0%
Низкий
8 месяцев назад

Уязвимостей на страницу