CVE-2012-1605Deserialization of Untrusted Data in CMS

Severity
5.0MEDIUMNVD
EPSS
0.9%
top 23.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 4
Latest updateMay 17

Description

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via vectors related to "a missing signature (HMAC) for a request argument."

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Packagisttypo3/cms4.64.6.7+2
NVDtypo3/typo310 versions+9

🔴Vulnerability Details

3
GHSA
Typo3 Extbase Framework Unsafe Deserialization2022-05-17
OSV
Typo3 Extbase Framework Unsafe Deserialization2022-05-17
CVEList
CVE-2012-1605: The Extbase Framework in TYPO3 42012-09-04
CVE-2012-1605 — Deserialization of Untrusted Data | cvebase