PT-2024-40517 · Packagist · Typo3/Cms-Core

Published

2024-05-30

·

Updated

2024-05-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned.
Description The issue concerns the backend API configuration using Page TSconfig, which is susceptible to arbitrary code execution and cross-site scripting. An attacker can inject malicious sequences through TSconfig fields in page properties within backend forms. The tsconfig includes field is vulnerable to directory traversal, potentially allowing access to TSconfig settings. A valid backend user account with permission to modify pages.TSconfig and pages.tsconfig includes fields is required to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

XSS

Weakness Enumeration

Related Identifiers

GHSA-X428-565F-8XJ2

Affected Products

Typo3/Cms-Core