CVE-2023-38499
published 2023-07-25CVE-2023-38499: TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, and…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.88%
54.6th percentile
TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, and 12.4.4, in multi-site scenarios, enumerating the HTTP query parameters `id` and `L` allowed out-of-scope access to rendered content in the website frontend. For instance, this allowed visitors to access content of an internal site by adding handcrafted query parameters to the URL of a site that was publicly available. TYPO3 versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, 12.4.4 fix the problem.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| typo3 | cms-core | >= 10.0.0 < 10.4.39 | 10.4.39 |
| typo3 | cms-core | >= 11.0.0 < 11.5.30 | 11.5.30 |
| typo3 | cms-core | >= 12.0.0 < 12.4.4 | 12.4.4 |
| typo3 | cms-core | >= 9.4.0 < 9.5.42 | 9.5.42 |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | >= 10.0.0 < 10.4.39 | 10.4.39 |
| typo3 | typo3 | >= 11.0.0 < 11.5.30 | 11.5.30 |
| typo3 | typo3 | >= 12.0.0 < 12.4.4 | 12.4.4 |
| typo3 | typo3 | >= 9.4.0 < 9.5.42 | 9.5.42 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Information Disclosure due to Out-of-scope Site Resolution
osv·2023-07-25
CVE-2023-38499 [LOW] Information Disclosure due to Out-of-scope Site Resolution
Information Disclosure due to Out-of-scope Site Resolution
> ### CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C` (3.5)
### Problem
In multi-site scenarios, enumerating the HTTP query parameters `id` and `L` allowed out-of-scope access to rendered content in the website frontend. For instance, this allowed visitors to access content of an internal site by adding handcrafted query parameters to the URL of a site that was publicly available.
### Solution
Update to TYPO3 versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, 12.4.4 that fix the problem described above.
> ℹ️ **Strong security defaults - Manual actions required**
> Resolving sites by the `id` and `L` HTTP query parameters is now denied per default. However, it is still allowed to resolve a particular page by e.g. `h
GHSA
Information Disclosure due to Out-of-scope Site Resolution
ghsa·2023-07-25
CVE-2023-38499 [LOW] CWE-200 Information Disclosure due to Out-of-scope Site Resolution
Information Disclosure due to Out-of-scope Site Resolution
> ### CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C` (3.5)
### Problem
In multi-site scenarios, enumerating the HTTP query parameters `id` and `L` allowed out-of-scope access to rendered content in the website frontend. For instance, this allowed visitors to access content of an internal site by adding handcrafted query parameters to the URL of a site that was publicly available.
### Solution
Update to TYPO3 versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, 12.4.4 that fix the problem described above.
> ℹ️ **Strong security defaults - Manual actions required**
> Resolving sites by the `id` and `L` HTTP query parameters is now denied per default. However, it is still allowed to resolve a particular page by e.g. `h
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/TYPO3/typo3/commit/702e2debd4b28f9cdb540544565fe6a8627ccb6ahttps://github.com/TYPO3/typo3/security/advisories/GHSA-jq6g-4v5m-wm9rhttps://typo3.org/security/advisory/typo3-core-sa-2023-003https://github.com/TYPO3/typo3/commit/702e2debd4b28f9cdb540544565fe6a8627ccb6ahttps://github.com/TYPO3/typo3/security/advisories/GHSA-jq6g-4v5m-wm9rhttps://typo3.org/security/advisory/typo3-core-sa-2023-003
2023-07-25
Published