7.5
CVE-2014-6290
- EPSS 0.62%
- Veröffentlicht 03.10.2014 14:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to have unspecified impact via vectors related to an "insecure unserialize" issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
News Project ≫ News SwPlatformtypo3 Version <= 3.5.1
News Project ≫ News Version3.0.0 SwPlatformtypo3
News Project ≫ News Version3.0.1 SwPlatformtypo3
News Project ≫ News Version3.1.0 SwPlatformtypo3
News Project ≫ News Version3.2.0 SwPlatformtypo3
News Project ≫ News Version3.2.1 SwPlatformtypo3
News Project ≫ News Version3.4.0 SwPlatformtypo3
News Project ≫ News Version3.5.0 SwPlatformtypo3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.62% | 0.696 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.