Typo3 Cms-Core vulnerabilities
85 known vulnerabilities affecting typo3/cms-core.
Total CVEs
85
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH21MEDIUM57LOW7
Vulnerabilities
Page 3 of 5
CVE-2019-11832HIGH≥ 8.0.0, < 8.7.25≥ 9.0.0, < 9.5.62022-05-24
CVE-2019-11832 [HIGH] CWE-20 TYPO3 Image Processing susceptible to Code Execution
TYPO3 Image Processing susceptible to Code Execution
TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 is susceptible to remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.
For a successful exploit, the GhostScript binary `gs` must be available on the server system.
ghsaosv
CVE-2019-12748MEDIUM≥ 8.0.0, < 8.7.27≥ 9.0.0, < 9.5.82022-05-24
CVE-2019-12748 [MEDIUM] CWE-79 Typo3 Cross-Site Scripting in Link Handling
Typo3 Cross-Site Scripting in Link Handling
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.
ghsaosv
CVE-2019-19850MEDIUM≥ 8.0, < 8.7.30≥ 9.0, < 9.5.12+1 more2022-05-24
CVE-2019-19850 [MEDIUM] TYPO3 SQL Injection in low-level Query Generator
TYPO3 SQL Injection in low-level Query Generator
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the system extension ext:lowlevel installed, and a valid backend user who has administrator privileges.
ghsaosv
CVE-2019-19848MEDIUM≥ 10.0.0, < 10.2.2≥ 8.0.0, < 8.7.30+1 more2022-05-24
CVE-2019-19848 [MEDIUM] CWE-22 TYPO3 Directory Traversal on ZIP extraction
TYPO3 Directory Traversal on ZIP extraction
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.)
ghsaosv
CVE-2013-1842HIGH≥ 4.5.0, < 4.5.24≥ 4.6.0, < 4.6.17+2 more2022-05-17
CVE-2013-1842 [HIGH] CWE-89 TYPO3 SQL injection vulnerability in the Extbase Framework
TYPO3 SQL injection vulnerability in the Extbase Framework
SQL injection vulnerability in the Extbase Framework in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "the Query Object Model and relation values."
ghsaosv
CVE-2013-1843MEDIUM≥ 4.5.0, < 4.5.24≥ 4.6.0, < 4.6.17+2 more2022-05-17
CVE-2013-1843 [MEDIUM] CWE-601 TYPO3 Open redirect vulnerability in the Access tracking mechanism
TYPO3 Open redirect vulnerability in the Access tracking mechanism
Open redirect vulnerability in the Access tracking mechanism in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ghsaosv
CVE-2013-7080MEDIUM≥ 4.5.0, < 4.5.31≥ 4.6.0, < 4.7.16+1 more2022-05-17
CVE-2013-7080 [MEDIUM] TYPO3 is vulnerable to Mass Assignment in the Extension table administration library
TYPO3 is vulnerable to Mass Assignment in the Extension table administration library
The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."
ghsaosv
CVE-2013-7077MEDIUM≥ 6.0, < 6.0.12≥ 6.1, < 6.1.72022-05-17
CVE-2013-7077 [MEDIUM] CWE-79 TYPO3 Cross-site scripting (XSS) vulnerability in the Backend User Administration Module
TYPO3 Cross-site scripting (XSS) vulnerability in the Backend User Administration Module
Cross-site scripting (XSS) vulnerability in the Backend User Administration Module in TYPO3 6.0.x before 6.0.12 and 6.1.x before 6.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ghsaosv
CVE-2013-4320MEDIUM≥ 6.0, < 6.0.9≥ 6.1, < 6.1.42022-05-17
CVE-2013-4320 [MEDIUM] CWE-284 TYPO3 Improper Access Management in the File Abstraction Layer
TYPO3 Improper Access Management in the File Abstraction Layer
The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenticated users to create or read arbitrary files via a crafted URL.
ghsaosv
CVE-2010-5104MEDIUM≥ 4.2.0, < 4.2.16≥ 4.3.0, < 4.3.9+1 more2022-05-17
CVE-2010-5104 [MEDIUM] CWE-200 TYPO3 Sensitive Information Disclosure via escapeStrForLike method
TYPO3 Sensitive Information Disclosure via escapeStrForLike method
The escapeStrForLike method in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly escape input when the MySQL database is set to sql_mode NO_BACKSLASH_ESCAPES, which allows remote attackers to obtain sensitive information via wildcard characters in a LIKE query.
ghsaosv
CVE-2013-7081MEDIUM≥ 4.5.0, < 4.5.31≥ 4.7.0, < 4.7.16+2 more2022-05-17
CVE-2013-7081 [MEDIUM] CWE-284 TYPO3 Improper Access Control vulnerability
TYPO3 Improper Access Control vulnerability
The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated editors to generate arbitrary HMAC signatures and bypass intended access restrictions via unspecified vectors.
ghsaosv
CVE-2013-7078LOW≥ 4.5.0, < 4.5.31≥ 4.7.0, < 4.7.16+2 more2022-05-17
CVE-2013-7078 [LOW] CWE-79 TYPO3 Cross-site scripting (XSS) vulnerability in the Extbase Framework
TYPO3 Cross-site scripting (XSS) vulnerability in the Extbase Framework
Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in the Extbase Framework in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6, when the Rewritten Property Mapper is enabled, allows remote attackers to inject arbitrary web script
ghsaosv
CVE-2009-3633MEDIUM≥ 0, ≤ 4.0.13≥ 4.1.0, < 4.1.13+2 more2022-05-02
CVE-2009-3633 [MEDIUM] CWE-352 TYPO3 API function vulnerable to Cross-site Scripting
TYPO3 API function vulnerable to Cross-site Scripting
Cross-site scripting (XSS) vulnerability in the `t3lib_div::quoteJSvalue` API function in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the sanitizing algorithm.
ghsaosv
CVE-2008-2717MEDIUM≥ 4.0.0, < 4.0.9≥ 4.1.0, < 4.1.7+1 more2022-05-01
CVE-2008-2717 [MEDIUM] CWE-434 TYPO3 Unrestricted File Upload vulnerability
TYPO3 Unrestricted File Upload vulnerability
TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.
ghsaosv
CVE-2010-3673MEDIUM≥ 0, < 4.2.13≥ 4.3, < 4.3.4+1 more2022-04-21
CVE-2010-3673 [MEDIUM] CWE-200 TYPO3 is vulnerable to Information Disclosure in the HTML mailing API
TYPO3 is vulnerable to Information Disclosure in the HTML mailing API
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.
ghsaosv
CVE-2021-41113HIGHCVSS 8.8≥ 11.2.0, < 11.5.02021-10-05
CVE-2021-41113 [HIGH] CWE-309 Cross-Site-Request-Forgery in Backend
Cross-Site-Request-Forgery in Backend
> ### Meta
> * CVSS: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C` (8.2)
### Problem
It has been discovered that the new TYPO3 v11 feature that allows users to create and share [deep links in the backend user interface](https://typo3.org/article/typo3-version-112-escape-the-orbit#c12178) is vulnerable to cross-site-request-forgery.
The impact is the same as described in [TY
ghsaosv
CVE-2021-41114MEDIUMCVSS 5.0≥ 11.0.0, < 11.5.02021-10-05
CVE-2021-41114 [MEDIUM] CWE-20 HTTP Host Header Injection
HTTP Host Header Injection
### Meta
* CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:O/RC:C` (3.5)
### Problem
It has been discovered that TYPO3 CMS is susceptible to host spoofing due to improper validation of the HTTP _Host_ header. TYPO3 uses the HTTP _Host_ header, for example, to generate absolute URLs during the frontend rendering process. Since the host header itself is provided by the client, it can be forged to any
ghsaosv
CVE-2021-32768MEDIUM≥ 7.0.0, < 7.6.53≥ 8.0.0, < 8.7.42+3 more2021-08-19
CVE-2021-32768 [MEDIUM] CWE-79 Cross-Site Scripting via Rich-Text Content
Cross-Site Scripting via Rich-Text Content
> ### Meta
> * CVSS: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC` (5.7)
### Problem
Failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website frontend is vulnerable to cross-site scripting. Corresponding rendering instructions via TypoScript functionality _[HTMLparser](https://docs.typo3.org/m/typo3/ref
ghsaosv
CVE-2021-32767MEDIUM≥ 7.0.0, < 7.6.52≥ 8.0.0, < 8.7.41+3 more2021-07-26
CVE-2021-32767 [MEDIUM] CWE-532 Information Disclosure in User Authentication
Information Disclosure in User Authentication
> ### Meta
> * CVSS: `AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C` (4.9)
### Problem
It has been discovered that user credentials have been logged as plaintext when explicitly using log level debug, which is not the _default_ configuration.
### Solution
Update to TYPO3 versions 7.6.52 ELTS, 8.7.41 ELTS, 9.5.28, 10.4.18, 11.3.1 that fix the problem described.
### C
ghsaosv
CVE-2021-32669MEDIUM≥ 8.0.0, < 8.7.41≥ 9.0.0, < 9.5.28+2 more2021-07-22
CVE-2021-32669 [MEDIUM] CWE-79 Cross-Site Scripting in Backend Grid View
Cross-Site Scripting in Backend Grid View
### Problem
Failing to properly encode settings for _backend layouts_, the corresponding grid view is vulnerable to persistent cross-site scripting. A valid backend user account is needed to exploit this vulnerability.
### Solution
Update to TYPO3 versions 8.7.41 ELTS, 9.5.28, 10.4.18, 11.3.1 that fix the problem described.
### Credits
Thanks to TYPO3 core merger Oliver Bartsch w
ghsaosv