{"id":"CVE-2019-11832","aliases":["GHSA-3w4h-r27h-4r2w"],"url":"https://o3.security/vulnerability/CVE-2019-11832","summary":"TYPO3 Image Processing susceptible to Code Execution","details":"TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.","published":"2019-05-09T05:29:01.957Z","modified":"2026-08-07T14:49:50.468747Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.03917,"percentile":0.89261,"asOf":"2026-07-31"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"8.7.25"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"9.5.6"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"8.7.25"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"9.5.6"}],"fix":null,"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/108305"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2019-012/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:49:50.468747Z"}}