PT-2024-40517 · Packagist · Typo3/Cms-Core
Published
2024-05-30
·
Updated
2024-05-30
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
No specific software or versions are mentioned.
Description
The issue concerns the backend API configuration using Page TSconfig, which is susceptible to arbitrary code execution and cross-site scripting. An attacker can inject malicious sequences through TSconfig fields in page properties within backend forms. The
tsconfig includes field is vulnerable to directory traversal, potentially allowing access to TSconfig settings. A valid backend user account with permission to modify pages.TSconfig and pages.tsconfig includes fields is required to exploit this issue.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Typo3/Cms-Core