QID 996679
Date Published: 2024-01-15
QID 996679: PHP (Composer) Security Update for typo3/cms (GHSA-2hp4-8h6h-93rr)
The Backend History Module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 does not properly restrict access, which allows remote authenticated editors to read the history of arbitrary records via a crafted URL.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-2hp4-8h6h-93rr for updates and patch information.
Vendor References
- GHSA-2hp4-8h6h-93rr -
github.com/advisories/GHSA-2hp4-8h6h-93rr
CVEs related to QID 996679
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2hp4-8h6h-93rr | typo3/cms |
|