{"id":"GHSA-67wg-6j7r-mqh8","aliases":[],"url":"https://o3.security/vulnerability/GHSA-67wg-6j7r-mqh8","summary":"Arbitrary Code Execution in TYPO3 CMS","details":"Due to a missing file extension in the fileDenyPattern, backend user are allowed to upload *.pht files which can be executed in certain web server setups. The new default fileDenyPattern is the following, which might have been overridden in the TYPO3 Install Tool.\n```\n\\.(php[3-7]?|phpsh|phtml|pht)(\\..*)?$|^\\.htaccess$\n```","published":"2024-06-05T15:07:09Z","modified":"2024-12-02T05:47:58.746494Z","cvss":{"score":9.9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"7.6.22"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"8.7.5"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2017-09-05-4.yaml"},{"type":"PACKAGE","url":"https://github.com/TYPO3/typo3"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2017-007"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:47:58.746494Z"}}