PT-2024-40437 · Typo3 · Typo3
Published
2024-06-05
·
Updated
2024-06-05
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Typo3 (affected versions not specified)
Description
The issue concerns the exposure of sensitive directories to the publicly accessible document root. It is recommended to configure a dedicated web folder in composer-managed installations and avoid exposing the complete typo3 src sources folder in the document root.
Recommendations
For all affected versions, ensure that the vendor directory is not exposed to the publicly accessible document root.
Configure a dedicated web folder in composer-managed installations to prevent exposure of sensitive files.
Restrict access to the typo3 src sources folder to prevent it from being accessible in the document root.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typo3