PT-2024-40437 · Typo3 · Typo3

Published

2024-06-05

·

Updated

2024-06-05

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Typo3 (affected versions not specified)
Description The issue concerns the exposure of sensitive directories to the publicly accessible document root. It is recommended to configure a dedicated web folder in composer-managed installations and avoid exposing the complete typo3 src sources folder in the document root.
Recommendations For all affected versions, ensure that the vendor directory is not exposed to the publicly accessible document root. Configure a dedicated web folder in composer-managed installations to prevent exposure of sensitive files. Restrict access to the typo3 src sources folder to prevent it from being accessible in the document root.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-QMWF-J7G7-F5JW

Affected Products

Typo3