QID 997574
Date Published: 2024-03-04
QID 997574: PHP (Composer) Security Update for typo3/cms (GHSA-3w4h-r27h-4r2w)
TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 is susceptible to remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick. For a successful exploit, the GhostScript binary gs must be available on the server system.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-3w4h-r27h-4r2w for updates and patch information.
Vendor References
- GHSA-3w4h-r27h-4r2w -
github.com/advisories/GHSA-3w4h-r27h-4r2w
CVEs related to QID 997574
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3w4h-r27h-4r2w | typo3/cms |
|