CVE-2022-31046Sensitive Information Exposure in Typo3

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 64.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14
Latest updateJun 17

Description

TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, the export functionality fails to limit the result set to allowed columns of a particular database table. This way, authenticated users can export internal details of database tables they already have access to. TYPO3 versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, 11.5.11 fix the problem described above. In order to address this issue, access to mentione

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

Packagisttypo3/cms10.0.010.4.29+1
NVDtypo3/typo37.0.07.6.57+4
Packagisttypo3/cms-core7.0.07.6.57+4
CVEListV5typo3/typo35 versions+4

Patches

🔴Vulnerability Details

3
GHSA
Information Disclosure via Export Module2022-06-17
OSV
Information Disclosure via Export Module2022-06-17
CVEList
Information Disclosure via Export Module in TYPO3 CMS2022-06-14
CVE-2022-31046 — Sensitive Information Exposure | cvebase