CVE-2023-38499
Summary
| CVE | CVE-2023-38499 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-25 21:15:00 UTC |
| Updated | 2023-08-02 19:11:00 UTC |
| Description | TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, and 12.4.4, in multi-site scenarios, enumerating the HTTP query parameters `id` and `L` allowed out-of-scope access to rendered content in the website frontend. For instance, this allowed visitors to access content of an internal site by adding handcrafted query parameters to the URL of a site that was publicly available. TYPO3 versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, 12.4.4 fix the problem. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Information Disclosure due to Out-of-scope Site Resolution · Advisory · TYPO3/typo3 · GitHub | MISC | github.com | |
| [SECURITY] Avoid out-of-scope page access for non-matching site · TYPO3/typo3@702e2de · GitHub | MISC | github.com | |
| TYPO3-CORE-SA-2023-003: Information Disclosure due to Out-of-scope Site Resolution | MISC | typo3.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 691230 Free Berkeley Software Distribution (FreeBSD) Security Update for typo3 (b1ac663f-3aa9-11ee-b887-b42e991fc52e)