QID 996448

Date Published: 2023-12-28

QID 996448: PHP (Composer) Security Update for typo3/cms-core (GHSA-3gjc-mp82-fj4q)

In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with ../../../ in data[sys_file_storage]*[data][sDEF][lDEF][basePath][vDEF].

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.9 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-3gjc-mp82-fj4q for updates and patch information.
    Vendor References

    CVEs related to QID 996448

    Software Advisories
    Advisory ID Software Component Link