7.5
CVE-2014-6290
- EPSS 1.31%
- Veröffentlicht 03.10.2014 14:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to have unspecified impact via vectors related to an "insecure unserialize" issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
News Project ≫ News SwPlatform typo3 Version <= 3.5.1
News Project ≫ News Version 3.0.0 SwPlatform typo3
News Project ≫ News Version 3.0.1 SwPlatform typo3
News Project ≫ News Version 3.1.0 SwPlatform typo3
News Project ≫ News Version 3.2.0 SwPlatform typo3
News Project ≫ News Version 3.2.1 SwPlatform typo3
News Project ≫ News Version 3.4.0 SwPlatform typo3
News Project ≫ News Version 3.5.0 SwPlatform typo3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.31% | 0.669 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://typo3.org/extensions/repository/view/tt_news
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-003/