{"id":"CVE-2023-38499","aliases":["BIT-typo3-2023-38499","GHSA-jq6g-4v5m-wm9r"],"url":"https://o3.security/vulnerability/CVE-2023-38499","summary":"typo3/cms-core Information Disclosure due to Out-of-scope Site Resolution","details":"> ### CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C` (3.5)\n\n### Problem\nIn multi-site scenarios, enumerating the HTTP query parameters `id` and `L` allowed out-of-scope access to rendered content in the website frontend. For instance, this allowed visitors to access content of an internal site by adding handcrafted query parameters to the URL of a site that was publicly available.\n\n### Solution\nUpdate to TYPO3 versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, 12.4.4 that fix the problem described above.\n\n> ℹ️ **Strong security defaults - Manual actions required**\n> Resolving sites by the `id` and `L` HTTP query parameters is now denied per default. However, it is still allowed to resolve a particular page by e.g. `https://example.org/?id=123&L=0` - as long as the `page-id 123` is in the scope of the site configured for the `base-url example.org`.\n> The new feature flag `security.frontend.allowInsecureSiteResolutionByQueryParameters` - which is disabled per default - can be used to reactivate the previous behavior.\n\n### Credits\nThanks to Garvin Hicking who reported this issue, and to TYPO3 core & security team members Oliver Hader and Benjamin Franzke who fixed the issue.\n\n### References\n* [TYPO3-CORE-SA-2023-003](https://typo3.org/security/advisory/typo3-core-sa-2023-003)\n","published":"2023-07-25T20:54:41.648Z","modified":"2026-08-27T03:30:55.162806936Z","cvss":{"score":3.7,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":{"score":0.01069,"percentile":0.63202,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"9.5.42"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"10.4.39"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"11.5.30"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"12.4.4"}],"fix":{"url":"https://github.com/TYPO3/typo3/commit/702e2debd4b28f9cdb540544565fe6a8627ccb6a","label":"TYPO3/typo3@702e2de"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38499.json"},{"type":"ADVISORY","url":"https://github.com/TYPO3/typo3/security/advisories/GHSA-jq6g-4v5m-wm9r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38499"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2023-003"},{"type":"FIX","url":"https://github.com/TYPO3/typo3/commit/702e2debd4b28f9cdb540544565fe6a8627ccb6a"},{"type":"PACKAGE","url":"https://github.com/TYPO3/typo3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:30:55.162806936Z"}}