CVE-2011-4904Improper Input Validation in Typo3

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 53.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 6
Latest updateApr 22

Description

TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

Packagisttypo3/cms4.5.04.5.4+1
NVDtypo3/typo34.4.04.4.9+1
CVEListV5typo3/typo3before 4.5.4

🔴Vulnerability Details

3
OSV
Typo3 Improper Access Control2022-04-22
GHSA
Typo3 Improper Access Control2022-04-22
CVEList
CVE-2011-4904: TYPO3 before 42019-11-06
CVE-2011-4904 — Improper Input Validation in Typo3 | cvebase