{"id":"GHSA-gwfx-p7mr-f92v","aliases":[],"url":"https://o3.security/vulnerability/GHSA-gwfx-p7mr-f92v","summary":"Missing Access Check in TYPO3 CMS","details":"Extbase request handling fails to implement a proper access check for requested controller/ action combinations, which makes it possible for an attacker to execute arbitrary Extbase actions by crafting a special request. To successfully exploit this vulnerability, an attacker must have access to at least one Extbase plugin or module action in a TYPO3 installation. The missing access check inevitably leads to information disclosure or remote code execution, depending on the action that an attacker is able to execute.","published":"2024-06-05T14:22:26Z","modified":"2024-12-02T05:39:49.717320Z","cvss":{"score":9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"6.2.25"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"7.6.8"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"8.1.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2016-05-24-1.yaml"},{"type":"WEB","url":"https://web.archive.org/web/20160606110438/https://typo3.org/teamssecuritysecurity-bulletins/security-bulletins-single-view/article/missing-access-check-in-typo3-cms"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:39:49.717320Z"}}