Typo3 Backend XSS Vulnerability
Moderate severity
GitHub Reviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Jan 23, 2024
Package
Affected versions
>= 3.3.0, < 3.9.0
>= 4.0, < 4.0.12
>= 4.1.0, < 4.1.10
>= 4.2.0, < 4.2.6
= 4.3alpha1
Patched versions
4.0.12
4.1.10
4.2.6
Description
Published by the National Vulnerability Database
Mar 5, 2009
Published to the GitHub Advisory Database
May 2, 2022
Reviewed
Jan 23, 2024
Last updated
Jan 23, 2024
An Information Disclosure vulnerability in jumpUrl mechanism, used to track access on web pages and provided files, allows a remote attacker to read arbitrary files on a host.
The expected value of a mandatory hash secret, intended to invalidate such requests, is exposed to remote users allowing them to bypass access control by providing the correct value.
There's no authentication required to exploit this vulnerability. The vulnerability allows to read any file, the web server user account has access to.
References