CVE-2010-3664 – typo3/cms-backend
Package
Manager: composer
Name: typo3/cms-backend
Vulnerable Version: >=0 <4.1.14 || >=4.2.0 <4.2.13 || >=4.3.0 <4.3.4 || >=4.4.0 <4.4.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00428 pctl0.61617
Details
TYPO3 is vulnerable to Information Disclosure on the backend TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.
Metadata
Created: 2022-04-21T01:57:47Z
Modified: 2024-02-06T23:22:30Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-8xp9-99h5-4vcg/GHSA-8xp9-99h5-4vcg.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-8xp9-99h5-4vcg
Finding: F038
Auto approve: 1