QID 997157
Date Published: 2024-02-09
QID 997157: PHP (Composer) Security Update for typo3/cms (GHSA-w736-qv86-vq94)
The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote attackers to read arbitrary files via unspecified vectors.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-w736-qv86-vq94 for updates and patch information.
Vendor References
- GHSA-w736-qv86-vq94 -
github.com/advisories/GHSA-w736-qv86-vq94
CVEs related to QID 997157
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w736-qv86-vq94 | typo3/cms |
|