{"id":"GHSA-9rx9-7fmh-gj3g","aliases":[],"url":"https://o3.security/vulnerability/GHSA-9rx9-7fmh-gj3g","summary":"TYPO3 Broken Access Control in Localization Handling","details":"It has been discovered that backend users having limited access to specific languages are capable of modifying and creating pages in the default language which actually should be disallowed. A valid backend user account is needed in order to exploit this vulnerability.","published":"2024-05-30T15:47:57Z","modified":"2024-12-05T05:42:59.678333Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"8.7.23"}],"fix":{"url":"https://github.com/TYPO3-CMS/core/commit/64b1b5dc2f7cacb2ba39b74081f4179d6393b2bf","label":"TYPO3-CMS/core@64b1b5d"},"references":[{"type":"WEB","url":"https://github.com/TYPO3-CMS/core/commit/64b1b5dc2f7cacb2ba39b74081f4179d6393b2bf"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/2019-01-22-3.yaml"},{"type":"PACKAGE","url":"https://github.com/TYPO3-CMS/core"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2019-003"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:42:59.678333Z"}}