CVE-2013-4250Improper Input Validation in CMS

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 39.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 20
Latest updateMay 17

Description

The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages2 packages

Packagisttypo3/cms6.0.06.0.8+1
NVDtypo3/typo312 versions+11

🔴Vulnerability Details

4
OSV
TYPO3 doesn't properly check file extensions2022-05-17
GHSA
TYPO3 doesn't properly check file extensions2022-05-17
GHSA
TYPO3 vulnerable to remote authenticated arbitrary code execution2022-05-17
CVEList
CVE-2013-4250: The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 62014-05-20
CVE-2013-4250 — Improper Input Validation in Typo3 CMS | cvebase