CVE-2024-34537Improper Validation of Syntactic Correctness of Input in Typo3

Severity
4.9MEDIUMNVD
EPSS
0.2%
top 51.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 28

Description

TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

Packagisttypo3/cms-backend13.0.013.3.1+3
NVDtypo3/typo310.0.010.4.46+3

🔴Vulnerability Details

3
CVEList
CVE-2024-34537: TYPO3 before 132024-10-28
OSV
Denial of Service in TYPO3 Bookmark Toolbar2024-10-08
GHSA
Denial of Service in TYPO3 Bookmark Toolbar2024-10-08
CVE-2024-34537 — Typo3 vulnerability | cvebase