CVE-2024-22188Code Injection in Typo3

Severity
7.2HIGHNVD
EPSS
0.7%
top 28.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 5

Description

TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

NVDtypo3/typo38.0.08.7.57+5
Packagisttypo3/cms-core8.0.08.7.57+5

🔴Vulnerability Details

3
CVEList
CVE-2024-22188: TYPO3 before 132024-03-05
GHSA
TYPO3 Install Tool vulnerable to Code Execution2024-02-13
OSV
TYPO3 Install Tool vulnerable to Code Execution2024-02-13
CVE-2024-22188 — Code Injection in Typo3 | cvebase