PT-2024-20761 · Typo3 · Typo3

·

CVE-2024-25120

·

Published

2024-02-13

·

Updated

2024-10-16

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions prior to 8.7.57 ELTS TYPO3 versions prior to 9.5.46 ELTS TYPO3 versions prior to 10.4.43 ELTS TYPO3 versions prior to 11.5.35 LTS TYPO3 versions prior to 12.4.11 LTS TYPO3 versions prior to 13.0.1
Description The TYPO3-specific t3:// URI scheme could be used to access resources outside of the users' permission scope, including files, folders, pages, and records, if a valid link-handling configuration was provided. Exploiting this issue requires a valid backend user account.
Recommendations Update to TYPO3 version 8.7.57 ELTS or later Update to TYPO3 version 9.5.46 ELTS or later Update to TYPO3 version 10.4.43 ELTS or later Update to TYPO3 version 11.5.35 LTS or later Update to TYPO3 version 12.4.11 LTS or later Update to TYPO3 version 13.0.1 or later As a temporary workaround, consider restricting access to the t3:// URI scheme until a patch is available.

Exploit

Fix

Improper Access Control

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-25120
GHSA-WF85-8HX9-GJ7C

Affected Products

Typo3