Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-30451
HistoryDec 25, 2023 - 5:15 a.m.

Directory traversal

2023-12-2505:15:00
PRIOn knowledge base
www.prio-n.com
6
typo3
filelist
directory traversal
vulnerability
baseuri
11.5.24
security issue

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.8%

In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with …/…/…/ in data[sys_file_storage]*[data][sDEF][lDEF][basePath][vDEF].

CPENameOperatorVersion
typo3eq11.5.24

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.8%