7.2
CVSSv3

CVE-2019-19848

Published: 17/12/2019 Updated: 23/12/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists in TYPO3 prior to 8.7.30, 9.x prior to 9.5.12, and 10.x prior to 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

typo3 typo3