{"api_version":"1","generated_at":"2026-07-23T04:28:21+00:00","cve":"CVE-2017-6370","urls":{"html":"https://cve.report/CVE-2017-6370","api":"https://cve.report/api/cve/CVE-2017-6370.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-6370","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-6370"},"summary":{"title":"CVE-2017-6370","description":"TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.","state":"PUBLISHED","assigner":"mitre","published_at":"2017-03-17 17:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-319","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request","name":"https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"GitHub - faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request: TYPO3 v7.6.15 Unencrypted Login Request Assigned CVE Number: CVE-2017-6370","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/97071","name":"http://www.securityfocus.com/bid/97071","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"TYPO3 CVE-2017-6370 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-6370","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-6370","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"6370","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"typo3","cpe5":"typo3","cpe6":"7.6.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T15:25:49.256Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"97071","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/97071"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2017-03-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-03-27T09:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"97071","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/97071"},{"tags":["x_refsource_MISC"],"url":"https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-6370","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"97071","refsource":"BID","url":"http://www.securityfocus.com/bid/97071"},{"name":"https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request","refsource":"MISC","url":"https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2017-6370","datePublished":"2017-03-17T17:00:00.000Z","dateReserved":"2017-02-28T00:00:00.000Z","dateUpdated":"2024-08-05T15:25:49.256Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-03-17 17:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-319","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:typo3:typo3:7.6.15:*:*:*:*:*:*:*","matchCriteriaId":"83755CA5-630F-43F4-A584-4D4A4A8850E5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"6370","Ordinal":"1","Title":"CVE-2017-6370","CVE":"CVE-2017-6370","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"6370","Ordinal":"1","NoteData":"TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.","Type":"Description","Title":"CVE-2017-6370"},{"CveYear":"2017","CveId":"6370","Ordinal":"2","NoteData":"2017-03-17","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"6370","Ordinal":"3","NoteData":"2017-03-27","Type":"Other","Title":"Modified"}]}}}