Typo3

Typo3

214 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.06%
  • Veröffentlicht 25.07.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:13:42

TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, and 12.4.4, in multi-site scenarios, enumerating the HTTP query parameters `id` and `L` allowed out-o...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 07.02.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 07:48:26

TYPO3 is a free and open source Content Management Framework released under the GNU General Public License. In affected versions the TYPO3 core component `GeneralUtility::getIndpEnv()` uses the unfiltered server environment variable `PATH_INFO`, whic...

  • EPSS 0.04%
  • Veröffentlicht 14.12.2022 08:15:10
  • Zuletzt bearbeitet 21.11.2024 06:48:41

TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in different st...

  • EPSS 0.12%
  • Veröffentlicht 14.12.2022 08:15:10
  • Zuletzt bearbeitet 21.11.2024 06:48:41

TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When users reset their password using the corresponding password recovery functionality, existing sessions for that particular user ac...

  • EPSS 0.2%
  • Veröffentlicht 14.12.2022 08:15:10
  • Zuletzt bearbeitet 21.11.2024 06:48:42

TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Code Injection. Due to the lack of separating user-submitted data from the internal configuration in the...

  • EPSS 0.07%
  • Veröffentlicht 14.12.2022 08:15:10
  • Zuletzt bearbeitet 21.11.2024 06:48:42

TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are subject to Sensitive Information Disclosure. Due to the lack of handling user-submitted YAML placeholder expressions in the si...

  • EPSS 0.12%
  • Veröffentlicht 14.12.2022 08:15:09
  • Zuletzt bearbeitet 21.11.2024 06:48:41

TYPO3 is an open source PHP based web content management system. In versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1, requesting invalid or non-existing resources via HTTP triggers the page error handler, which again could retrieve content to b...

  • EPSS 0.2%
  • Veröffentlicht 13.09.2022 18:15:15
  • Zuletzt bearbeitet 21.11.2024 07:12:24

TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the expiration time of a password reset link for TYPO3 backend users has never been evaluated. As a result, a password reset link ...

  • EPSS 0.69%
  • Veröffentlicht 13.09.2022 18:15:15
  • Zuletzt bearbeitet 21.11.2024 07:12:24

TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `FileDumpController` (backend and frontend context) is vulnerable to cross-site scripting when malicious files are displayed u...

  • EPSS 0.69%
  • Veröffentlicht 13.09.2022 18:15:15
  • Zuletzt bearbeitet 21.11.2024 07:12:24

TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `f:asset.css` view helper is vulnerable to cross-site scripting when user input is passed as variables to the CSS. Update to T...