PT-2024-40334 · Packagist · Typo3/Cms
Published
2024-06-05
·
Updated
2024-06-05
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
No specific software or versions are mentioned in the provided descriptions.
Description
The issue concerns the backend API configuration using Page TSconfig, which is susceptible to arbitrary code execution and cross-site scripting. An attacker can exploit this by injecting malicious sequences through the TSconfig fields of page properties in backend forms. Specifically, the
tsconfig includes field is vulnerable to directory traversal, potentially leading to unauthorized access to TSconfig settings. A valid backend user account with permissions to modify pages.TSconfig and pages.tsconfig includes values is required to exploit this issue.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Typo3/Cms