PT-2010-5628 · Typo3 · Typo3

Gregor Kopf

·

Published

1970-01-01

·

Updated

2022-05-17

·

CVE-2010-3714

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions 4.2.x through 4.2.14 TYPO3 versions 4.3.x through 4.3.6 TYPO3 versions 4.4.x through 4.4.3
Description The issue is related to the jumpUrl implementation in tslib/class.tslib fe.php, which does not properly compare certain hash values during access-control decisions. This allows remote attackers to read arbitrary files via unspecified vectors. The vulnerability can be exploited remotely and may lead to a breach of confidentiality of protected information.
Recommendations For TYPO3 versions 4.2.x through 4.2.14, update to version 4.2.15 or later. For TYPO3 versions 4.3.x through 4.3.6, update to version 4.3.7 or later. For TYPO3 versions 4.4.x through 4.4.3, update to version 4.4.4 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01425
BDU:2015-02085
CVE-2010-3714
DSA-2121-1
GHSA-W736-QV86-VQ94

Affected Products

Typo3