Lucene search

K
osvGoogleOSV:GHSA-3GJC-MP82-FJ4Q
HistoryDec 25, 2023 - 6:30 a.m.

TYPO3 Arbitrary File Read via Directory Traversal

2023-12-2506:30:20
Google
osv.dev
8
typo3
arbitrary file read
directory traversal

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.8%

In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with ../../../ in data[sys_file_storage]*[data][sDEF][lDEF][basePath][vDEF].

CPENameOperatorVersion
typo3/cms-coreeq11.5.24

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.8%