{"id":"CVE-2017-14251","aliases":["GHSA-fh4q-hxrw-cjqq"],"url":"https://o3.security/vulnerability/CVE-2017-14251","summary":"TYPO3 Arbitrary Code Execution","details":"Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.","published":"2017-09-11T09:29:00.467Z","modified":"2026-08-27T03:47:23.801497753Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"7.6.22"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"8.7.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/100620"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1039295"},{"type":"ARTICLE","url":"http://blog.emaze.net/2017/12/typo3-unrestricted-file-upload-remote.html"},{"type":"EVIDENCE","url":"https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2017-007/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:47:23.801497753Z"}}