9.8

CVE-2019-16699

The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Code Execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sr Freecap ProjectSr Freecap Version >= 2.4.0 <= 2.4.5
Sr Freecap ProjectSr Freecap Version >= 2.5.0 <= 2.5.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.43% 0.821
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://extensions.typo3.org/extension/sr_freecap
Third Party Advisory
https://typo3.org/security/advisory/typo3-ext-sa-2019-018/
Third Party Advisory