NA

CVE-2023-30451

Published: 25/12/2023 Updated: 03/01/2024
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with ../../../ in data[sys_file_storage]*[data][sDEF][lDEF][basePath][vDEF].

Vulnerable Product Search on Vulmon Subscribe to Product

typo3 typo3 11.5.24

Exploits

TYPO3 version 11524 suffers from a path traversal vulnerability ...