Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5064
HistorySep 12, 2017 - 8:26 a.m.

Unauthorized File Upload

2017-09-1208:26:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.008 Low

EPSS

Percentile

81.5%

typo3/cms is vulnerable to unauthorized file upload. The library does not restrict files with the pht extension, allowing a malicious user to upload a .pht file to the application and execute arbitrary PHP script.

CPENameOperatorVersion
typo3/cmsle7.6.20
typo3/cmsle8.7.4

0.008 Low

EPSS

Percentile

81.5%