PT-2024-40334 · Packagist · Typo3/Cms

Published

2024-06-05

·

Updated

2024-06-05

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue concerns the backend API configuration using Page TSconfig, which is susceptible to arbitrary code execution and cross-site scripting. An attacker can exploit this by injecting malicious sequences through the TSconfig fields of page properties in backend forms. Specifically, the tsconfig includes field is vulnerable to directory traversal, potentially leading to unauthorized access to TSconfig settings. A valid backend user account with permissions to modify pages.TSconfig and pages.tsconfig includes values is required to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-HWW5-6X85-MC24

Affected Products

Typo3/Cms