6
CVSSv2

CVE-2010-3716

Published: 25/10/2010 Updated: 27/10/2010
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The be_user_creation task in TYPO3 4.2.x prior to 4.2.15 and 4.3.x prior to 4.3.7 allows remote authenticated users to gain privileges via a crafted POST request that creates a user account with arbitrary group memberships.

Vulnerable Product Search on Vulmon Subscribe to Product

typo3 typo3 4.2.1

typo3 typo3 4.2.4

typo3 typo3 4.2.10

typo3 typo3 4.2.11

typo3 typo3 4.2.8

typo3 typo3 4.2.0

typo3 typo3 4.2.13

typo3 typo3 4.3.0

typo3 typo3 4.2.3

typo3 typo3 4.2.5

typo3 typo3 4.2.6

typo3 typo3 4.2.7

typo3 typo3 4.3.1

typo3 typo3 4.3.2

typo3 typo3 4.3.3

typo3 typo3 4.3.4

typo3 typo3 4.3.5

typo3 typo3 4.2.9

typo3 typo3 4.2.2

typo3 typo3 4.2.12

typo3 typo3 4.2.14

typo3 typo3 4.3.6

Vendor Advisories

Several remote vulnerabilities have been discovered in TYPO3 The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-3714 Multiple remote file disclosure vulnerabilities in the jumpUrl mechanism and the Extension Manager allowed attackers to read files with the privileges of the account under which the web ...