CVE-2013-4321Code Injection in CMS

CWE-94Code Injection4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.5%
top 34.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 20
Latest updateMay 17

Description

The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors to execute arbitrary PHP code via unspecified characters in the file extension when renaming a file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4250.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages2 packages

Packagisttypo3/cms6.0.06.0.9+1
NVDtypo3/typo312 versions+11

🔴Vulnerability Details

3
OSV
TYPO3 vulnerable to remote authenticated arbitrary code execution2022-05-17
GHSA
TYPO3 vulnerable to remote authenticated arbitrary code execution2022-05-17
CVEList
CVE-2013-4321: The File Abstraction Layer (FAL) in TYPO3 62014-05-20
CVE-2013-4321 — Code Injection in Typo3 CMS | cvebase