CVE-2019-16699

The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Code Execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sr_freecap_project:sr_freecap:*:*:*:*:*:*:*:*
cpe:2.3:a:sr_freecap_project:sr_freecap:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:31

Type Values Removed Values Added
References () https://extensions.typo3.org/extension/sr_freecap - Third Party Advisory () https://extensions.typo3.org/extension/sr_freecap - Third Party Advisory
References () https://typo3.org/security/advisory/typo3-ext-sa-2019-018/ - Third Party Advisory () https://typo3.org/security/advisory/typo3-ext-sa-2019-018/ - Third Party Advisory

Information

Published : 2019-10-16 19:15

Updated : 2024-11-21 04:31


NVD link : CVE-2019-16699

Mitre link : CVE-2019-16699

CVE.ORG link : CVE-2019-16699


JSON object : View

Products Affected

sr_freecap_project

  • sr_freecap
CWE
CWE-20

Improper Input Validation