PT-2022-16037 · Typo3 · Typo3

Oliver Hader

·

Published

2022-12-13

·

Updated

2024-03-06

·

CVE-2022-23504

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions TYPO3 versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1
Description The issue is related to the lack of handling user-submitted YAML placeholder expressions in the site configuration backend module. This allows attackers to expose sensitive internal information, such as system configuration or HTTP request messages of other website visitors. A valid backend user account with administrator privileges is needed to exploit this issue.
Recommendations Update to TYPO3 versions 9.5.38 ELTS, 10.4.33, 11.5.20, or 12.1.1 to fix the problem. As a temporary workaround, consider restricting access to the site configuration backend module for users with administrator privileges until a patch is applied. Avoid using the YAML placeholder expressions feature in the site configuration backend module until the issue is resolved.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TYPO3-2022-23504
CVE-2022-23504
GHSA-8W3P-QH3X-6GJR

Affected Products

Typo3