PT-2022-16036 · Typo3 · Typo3
Sabine Deeken
·
Published
2022-12-13
·
Updated
2024-03-06
·
CVE-2022-23503
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TYPO3 versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1
Description
The issue concerns a Code Injection vulnerability in the Form Designer backend module of TYPO3, an open source PHP based web content management system. Due to the lack of separation between user-submitted data and internal configuration, it is possible to inject code instructions to be processed and executed via TypoScript as PHP code. The existence of individual TypoScript instructions for a particular form item, such as
formDefinitionOverrides, and a valid backend user account with access to the form module are needed to exploit this vulnerability.Recommendations
Update to TYPO3 versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, or 12.1.1 to fix the issue.
As a temporary workaround, consider restricting access to the Form Designer backend module to minimize the risk of exploitation.
Avoid using individual TypoScript instructions for particular form items until the issue is resolved.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typo3