Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ GHSA-f5rr-9r84-wwqf — cms

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Typo3 Broken Access Control in Import Module

It has been discovered that the Import/Export module is susceptible to broken access control. Regular backend users have access to import functionality which usually only is available to admin users or users having User TSconfig setting options.impexp.enableImportForNonAdminUser explicitly enabled.

Database content to be imported however was correctly checked against users’ permissions and not affected. However it was possible to upload files by-passing restrictions of the file abstraction layer (FAL) - however this did not affect executable files which have been correctly secured by fileDenyPattern.

Currently the only known vulnerability is to directly inject *.form.yaml files which could be used to trigger the vulnerability of TYPO3-CORE-SA-2018-003 (privilege escalation & SQL injection) - which requires the Form Framework (ext:form) being available on an according website. CVSSv3 scoring is based on this scenario.

A valid backend user account is needed in order to exploit this vulnerability.

Affected software

GHSA-f5rr-9r84-wwqf is recorded against 1 package.

  • typo3/cms (from 9.0.0 up to 9.5.8)

Timeline and source

Published on 5 June 2024 and last revised on 2 December 2024. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

github.com (Web)
github.com (Package)
typo3.org (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-06-05
Updated 2026-08-20
Modified 2024-12-02
Fix URL N/A

Affected Packages

Software From version Fixed in
typo3/cms 9.0.0 9.5.8

Similar Threats

Free Vulnerability Check

Is your site affected by GHSA-f5rr-9r84-wwqf?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against GHSA-f5rr-9r84-wwqf and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.