CVE-2014-3942Code Injection in CMS

CWE-94Code Injection4 documents4 sources
Severity
6.0MEDIUMNVD
EPSS
0.4%
top 36.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 3
Latest updateMay 14

Description

The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authenticated editors to execute arbitrary PHP code via a serialized PHP object.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages2 packages

Packagisttypo3/cms4.5.04.5.34+3
NVDtypo3/typo376 versions+75

🔴Vulnerability Details

3
OSV
TYPO3 Color Picker Wizard component allows remote authenticated editors to execute arbitrary PHP code2022-05-14
GHSA
TYPO3 Color Picker Wizard component allows remote authenticated editors to execute arbitrary PHP code2022-05-14
CVEList
CVE-2014-3942: The Color Picker Wizard component in TYPO3 42014-06-03
CVE-2014-3942 — Code Injection in Typo3 CMS | cvebase