PT-2025-3144 · Typo3 · Typo3

Gabriel Dimitrov

·

Publicado

2025-01-14

·

Atualizado

2025-08-26

·

CVE-2024-55893

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions prior to 11.5.42 ELTS TYPO3 versions prior to 12.4.25 LTS TYPO3 versions prior to 13.4.3 LTS
Description A vulnerability has been identified in the backend user interface functionality involving deep links, which is susceptible to Cross-Site Request Forgery (CSRF). State-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP method. Successful exploitation requires the victim to have an active session on the backend user interface and to be deceived into interacting with a malicious URL targeting the backend. This can occur when the user opens a malicious link or visits a compromised website while the security.backend.enforceReferrer feature is disabled or the BE/cookieSameSite configuration is set to lax or none. The vulnerability in the affected downstream component "Log Module" allows attackers to remove log entries.
Recommendations Update to TYPO3 version 11.5.42 ELTS to fix the problem described. Update to TYPO3 version 12.4.25 LTS to fix the problem described. Update to TYPO3 version 13.4.3 LTS to fix the problem described.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-55893
GHSA-CJFR-9F5R-3Q93

Produtos afetados

Typo3