Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45476
HistoryFeb 14, 2024 - 6:56 a.m.

Information Disclosure

2024-02-1406:56:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
typo3
information disclosure
encryptionkey
install tool
http request

4.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

TYPO3 is vulnerable to Information Disclosure. The vulnerability is due to the plaintext value of the $GLOBALS['SYS']['encryptionKey'] displayed in the TYPO3 Install Tool user interface. This allows an attacker to utilize the value to generate cryptographic hashes to verify the authenticity of HTTP request parameters.

4.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%