{"id":"CVE-2013-7080","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-7080","summary":"TYPO3 is vulnerable to Mass Assignment in the Extension table administration library","details":"The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka \"Mass Assignment.\"","published":"2022-05-17T04:54:37Z","modified":"2023-11-08T03:57:27.828722Z","cvss":null,"epss":{"score":0.01207,"percentile":0.65981,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"4.5.31"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"4.7.16"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"6.0.11"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-7080"},{"type":"PACKAGE","url":"https://github.com/TYPO3-CMS/core"},{"type":"WEB","url":"http://seclists.org/oss-sec/2013/q4/473"},{"type":"WEB","url":"http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004"},{"type":"WEB","url":"http://www.debian.org/security/2014/dsa-2834"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:57:27.828722Z"}}