PT-2023-31565 · Typo3 · Typo3

Publicado

2023-12-13

·

Atualizado

2023-12-13

·

CVE-2023-50461

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TYPO3 versions 9.5 and below TYPO3 versions 10.4 and above
Description The issue allows an authenticated user to write arbitrary page TSConfig for folders configured as "Direct Mail". This can lead to Configuration Injection in TYPO3 10.4 and above, and to Arbitrary Code Execution in TYPO3 9.5 and below. A valid backend user account with access to the "Configuration" backend module is required to exploit this issue.
Recommendations For TYPO3 versions 9.5 and below, consider restricting access to the "Configuration" backend module to minimize the risk of Arbitrary Code Execution. For TYPO3 versions 10.4 and above, consider disabling the writing of arbitrary page TSConfig for folders configured as "Direct Mail" until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-50461
GHSA-P6XX-FHFW-7MJ7

Produtos afetados

Typo3