{"id":"CVE-2021-21355","aliases":["BIT-typo3-2021-21355","GHSA-2r6j-862c-m2v2"],"url":"https://o3.security/vulnerability/CVE-2021-21355","summary":"Unrestricted File Upload in Form Framework","details":"\n### Problem\nDue to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary data with arbitrary file extensions - however, default _fileDenyPattern_ successfully blocked files like _.htaccess_ or _malicious.php_.\n\nTYPO3 Extbase extensions, which implement a file upload and do not implement a custom _TypeConverter_ to transform uploaded files into _FileReference_ domain model objects are affected by the vulnerability as well, since the _UploadedFileReferenceConverter_ of _ext:form_ handles the file upload and will accept files of any mime-type which are persisted to the default location.\n\nIn any way, uploaded files are placed in the default location _/fileadmin/user_upload/_, in most scenarios keeping the submitted filename - which allows attackers to directly reference files, or even correctly guess filenames used by other individuals, disclosing this information.\n\nNo authentication is required to exploit this vulnerability.\n\n### Solution\nUpdate to TYPO3 versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 that fix the problem described.\n\nType converter _UploadedFileReferenceConverter_ is not registered globally anymore and just handles uploaded files within the scope of the Form Framework. Guessable storage location has changed from _/fileadmin/user_upload/form\\_\\<random-hash\\>/_ to _/fileadmin/form_uploads/<random-40-bit>_. Allowed mime-types must match expected file extensions (e.g. _application/pdf_ must be _.pdf_, and cannot be _.html_).\n\nExtbase extensions, who rely on the global availability of the _UploadedFileReferenceConverter_ must now implement a custom _TypeConverter_ to handle file uploads or explicitly implement the ext:form _UploadedFileReferenceConverter_ with appropriate setting for accepted mime-types.\n\n### Credits\nThanks to Sebastian Michaelsen, Marc Lindemann, Oliver Eglseder, Markus Volkmer, Jakob Kunzmann, Johannes Regner, Richie Lee who reported this issue, and to TYPO3 core & security team members Oliver Hader & Benni Mack, as well as TYPO3 contributor Ralf Zimmermann who fixed the issue.\n\n### References\n* [TYPO3-CORE-SA-2021-002](https://typo3.org/security/advisory/typo3-core-sa-2021-002)","published":"2021-03-23T02:15:12.627Z","modified":"2026-08-27T03:49:17.734499516Z","cvss":{"score":8.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms-form","fixedVersion":"8.7.40"},{"ecosystem":"Packagist","name":"typo3/cms-form","fixedVersion":"9.5.25"},{"ecosystem":"Packagist","name":"typo3/cms-form","fixedVersion":"10.4.14"},{"ecosystem":"Packagist","name":"typo3/cms-form","fixedVersion":"11.1.1"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"10.4.14"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"11.1.1"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"9.5.25"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"10.4.14"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"11.1.1"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"9.5.25"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-2r6j-862c-m2v2"},{"type":"ADVISORY","url":"https://packagist.org/packages/typo3/cms-form"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2021-002"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21355"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2021-21355.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2021-21355.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:49:17.734499516Z"}}