Lucene search

K
cve[email protected]CVE-2023-47127
HistoryNov 14, 2023 - 8:15 p.m.

CVE-2023-47127

2023-11-1420:15:08
CWE-302
CWE-287
web.nvd.nist.gov
40
typo3
open source
web content management system
session cookie
vulnerability
cve-2023-47127
security advisory

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.5%

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two different sites. Eg. first.example.org and second.example.com. In affected versions a session cookie generated for the first site can be reused on the second site without requiring additional authentication. This vulnerability has been addressed in versions 8.7.55, 9.5.44, 10.4.41, 11.5.33, and 12.4.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected configurations

Vulners
NVD
Node
typo3typo3Range8.0.08.7.55
OR
typo3typo3Range9.0.09.5.44
OR
typo3typo3Range10.0.010.4.41
OR
typo3typo3Range11.0.011.5.33
OR
typo3typo3Range12.0.012.4.8
VendorProductVersionCPE
typo3typo3*cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
typo3typo3*cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
typo3typo3*cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
typo3typo3*cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
typo3typo3*cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "TYPO3",
    "product": "typo3",
    "versions": [
      {
        "version": ">= 8.0.0, < 8.7.55",
        "status": "affected"
      },
      {
        "version": ">= 9.0.0, < 9.5.44",
        "status": "affected"
      },
      {
        "version": ">= 10.0.0, < 10.4.41",
        "status": "affected"
      },
      {
        "version": ">= 11.0.0, < 11.5.33",
        "status": "affected"
      },
      {
        "version": ">= 12.0.0, < 12.4.8",
        "status": "affected"
      }
    ]
  }
]

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.5%