CVE-2013-7080
published 2013-12-23CVE-2013-7080: The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and…
PriorityP431medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.21%
64.5th percentile
The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."
Affected
64 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| typo3 | cms-core | >= 4.5.0 < 4.5.31 | 4.5.31 |
| typo3 | cms-core | >= 4.6.0 < 4.7.16 | 4.7.16 |
| typo3 | cms-core | >= 6.0.0 < 6.0.11 | 6.0.11 |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
TYPO3 is vulnerable to Mass Assignment in the Extension table administration library
osv·2022-05-17
CVE-2013-7080 [MEDIUM] TYPO3 is vulnerable to Mass Assignment in the Extension table administration library
TYPO3 is vulnerable to Mass Assignment in the Extension table administration library
The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."
GHSA
TYPO3 is vulnerable to Mass Assignment in the Extension table administration library
ghsa·2022-05-17
CVE-2013-7080 [MEDIUM] TYPO3 is vulnerable to Mass Assignment in the Extension table administration library
TYPO3 is vulnerable to Mass Assignment in the Extension table administration library
The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."
OSV
CVE-2013-7080: The creating record functionality in Extension table administration library (feuser_adminLib
osv·2013-12-23·CVSS 5.8
CVE-2013-7080 [MEDIUM] CVE-2013-7080: The creating record functionality in Extension table administration library (feuser_adminLib
The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/oss-sec/2013/q4/473http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004/http://www.debian.org/security/2014/dsa-2834http://seclists.org/oss-sec/2013/q4/473http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004/http://www.debian.org/security/2014/dsa-2834
2013-12-23
Published