Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-22188
HistoryMar 05, 2024 - 2:15 a.m.

Command injection

2024-03-0502:15:00
PRIOn knowledge base
www.prio-n.com
13
typo3
command injection
authenticated admin
system maintainer
arbitrary shell commands
install tool
web server privileges
8.7.57 elts
9.5.46 elts
10.4.43 elts
11.5.35 lts
12.4.11 lts

7.9 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.

7.9 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%