Lucene search

K
githubGitHub Advisory DatabaseGHSA-H934-F4M4-WC8X
HistoryJun 05, 2024 - 5:21 p.m.

Typo3 Information Disclosure in Page Tree

2024-06-0517:21:19
GitHub Advisory Database
github.com
1
typo3
information disclosure
page tree
backend users
read access
vulnerability
exploit

6.8 Medium

AI Score

Confidence

Low

It has been discovered backend users not having read access to specific pages still could see them in the page tree which actually should be disallowed. A valid backend user account is needed in order to exploit this vulnerability.

Affected configurations

Vulners
Node
typo3cms_poll_system_extensionRange<9.5.6
CPENameOperatorVersion
typo3/cmslt9.5.6

6.8 Medium

AI Score

Confidence

Low