{"id":"CVE-2023-38499","aliases":["BIT-typo3-2023-38499","GHSA-jq6g-4v5m-wm9r"],"url":"https://o3.security/vulnerability/CVE-2023-38499","summary":"typo3/cms-core Information Disclosure due to Out-of-scope Site Resolution","details":"TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, and 12.4.4, in multi-site scenarios, enumerating the HTTP query parameters `id` and `L` allowed out-of-scope access to rendered content in the website frontend. For instance, this allowed visitors to access content of an internal site by adding handcrafted query parameters to the URL of a site that was publicly available. TYPO3 versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, 12.4.4 fix the problem.","published":"2023-07-25T20:54:41.648Z","modified":"2026-08-08T03:47:41.217595131Z","cvss":{"score":3.7,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"9.5.42"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"10.4.39"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"11.5.30"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"12.4.4"}],"fix":{"url":"https://github.com/TYPO3/typo3/commit/702e2debd4b28f9cdb540544565fe6a8627ccb6a","label":"TYPO3/typo3@702e2de"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38499.json"},{"type":"ADVISORY","url":"https://github.com/TYPO3/typo3/security/advisories/GHSA-jq6g-4v5m-wm9r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38499"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2023-003"},{"type":"FIX","url":"https://github.com/TYPO3/typo3/commit/702e2debd4b28f9cdb540544565fe6a8627ccb6a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:41.217595131Z"}}