QID 996448
Date Published: 2023-12-28
QID 996448: PHP (Composer) Security Update for typo3/cms-core (GHSA-3gjc-mp82-fj4q)
In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with ../../../ in data[sys_file_storage]*[data][sDEF][lDEF][basePath][vDEF].
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-3gjc-mp82-fj4q for updates and patch information.
Vendor References
- GHSA-3gjc-mp82-fj4q -
github.com/advisories/GHSA-3gjc-mp82-fj4q
CVEs related to QID 996448
Software Advisories
| Advisory ID | Software | Component | Link |
|---|