Lucene search

K
githubGitHub Advisory DatabaseGHSA-C5WX-6C2C-F7RM
HistoryDec 13, 2022 - 5:11 p.m.

TYPO3 CMS vulnerable to Arbitrary Code Execution via Form Framework

2022-12-1317:11:46
CWE-94
GitHub Advisory Database
github.com
16
typo3
arbitrary code execution
form framework
typoscript
php code
exploit
update
elts
typo3-core-sa-2022-015

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

39.0%

Problem

Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend module, it was possible to inject code instructions to be processed and executed via TypoScript as PHP code.

The existence of individual TypoScript instructions for a particular form item (known as formDefinitionOverrides) and a valid backend user account with access to the form module are needed to exploit this vulnerability.

Solution

Update to TYPO3 versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1 that fix the problem described above.

References

Affected configurations

Vulners
Node
typo3typo3_cmsRange12.0.012.1.1
OR
typo3typo3_cmsRange11.0.011.5.20
OR
typo3typo3_cmsRange10.0.010.4.33
OR
typo3cms-coreRange12.0.012.1.1
OR
typo3cms-coreRange11.0.011.5.20
OR
typo3cms-coreRange10.0.010.4.33
OR
typo3cms-coreRange9.0.09.5.38
OR
typo3cms-coreRange8.0.08.7.49
VendorProductVersionCPE
typo3typo3_cms*cpe:2.3:a:typo3:typo3_cms:*:*:*:*:*:*:*:*
typo3cms-core*cpe:2.3:a:typo3:cms-core:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

39.0%