TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` URI scheme could be used to access resources outside of the users' permission scope. This encompassed files, folders, pages, and records (although only if a valid link-handling configuration was provided). Exploiting this vulnerability requires a valid backend user account. Users are advised to update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described. There are no known workarounds for this issue.
References
Link | Resource |
---|---|
https://docs.typo3.org/m/typo3/reference-typoscript/main/en-us/Functions/Typolink.html#resource-references | Third Party Advisory |
https://github.com/TYPO3/typo3/security/advisories/GHSA-wf85-8hx9-gj7c | Third Party Advisory |
https://typo3.org/security/advisory/typo3-core-sa-2024-005 | Vendor Advisory |
https://docs.typo3.org/m/typo3/reference-typoscript/main/en-us/Functions/Typolink.html#resource-references | Third Party Advisory |
https://github.com/TYPO3/typo3/security/advisories/GHSA-wf85-8hx9-gj7c | Third Party Advisory |
https://typo3.org/security/advisory/typo3-core-sa-2024-005 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 09:00
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.typo3.org/m/typo3/reference-typoscript/main/en-us/Functions/Typolink.html#resource-references - Third Party Advisory | |
References | () https://github.com/TYPO3/typo3/security/advisories/GHSA-wf85-8hx9-gj7c - Third Party Advisory | |
References | () https://typo3.org/security/advisory/typo3-core-sa-2024-005 - Vendor Advisory |
16 Oct 2024, 16:41
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* cpe:2.3:a:typo3:typo3:13.0.0:*:*:*:*:*:*:* |
|
First Time |
Typo3
Typo3 typo3 |
|
References | () https://docs.typo3.org/m/typo3/reference-typoscript/main/en-us/Functions/Typolink.html#resource-references - Third Party Advisory | |
References | () https://github.com/TYPO3/typo3/security/advisories/GHSA-wf85-8hx9-gj7c - Third Party Advisory | |
References | () https://typo3.org/security/advisory/typo3-core-sa-2024-005 - Vendor Advisory | |
CWE | NVD-CWE-noinfo |
13 Feb 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-13 23:15
Updated : 2024-11-21 09:00
NVD link : CVE-2024-25120
Mitre link : CVE-2024-25120
CVE.ORG link : CVE-2024-25120
JSON object : View
Products Affected
typo3
- typo3
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-284Improper Access Control
NVD-CWE-noinfo