CVE-2024-47780Incorrect Authorization in Typo3

Severity
4.3MEDIUMNVD
CNA3.1
EPSS
0.3%
top 50.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 8

Description

TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowed access to "everybody." However, affected users could not manipulate these pages. Users are advised to update to TYPO3 versions 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, 13.3.1 that fix the problem described. There are no known workarounds for th

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

Packagisttypo3/cms-backend13.0.013.3.1+3
NVDtypo3/typo310.0.010.4.46+3
CVEListV5typo3/typo34 versions+3

🔴Vulnerability Details

3
OSV
Information Disclosure in TYPO3 Page Tree2024-10-08
CVEList
Information Disclosure in TYPO3 Page Tree2024-10-08
GHSA
Information Disclosure in TYPO3 Page Tree2024-10-08
CVE-2024-47780 — Incorrect Authorization in Typo3 | cvebase