5
CVSSv2

CVE-2017-6370

Published: 17/03/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote malicious users to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.

Vulnerable Product Search on Vulmon Subscribe to Product

typo3 typo3 7.6.15

Github Repositories

TYPO3 v7.6.15 Unencrypted Login Request Assigned CVE Number: CVE-2017-6370

TYPO3-v7615-Unencrypted-Login-Request TYPO3 v7615 Unencrypted Login Request Assigned CVE Number: CVE-2017-6370