CVE-2017-14251 – typo3/cms
Package
Manager: composer
Name: typo3/cms
Vulnerable Version: >=7.6.0 <7.6.22 || >=8.0.0 <8.7.5
Severity
Level: High
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.03536 pctl0.87206
Details
TYPO3 Arbitrary Code Execution Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.
Metadata
Created: 2022-05-17T00:18:39Z
Modified: 2024-04-25T21:29:47Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-fh4q-hxrw-cjqq/GHSA-fh4q-hxrw-cjqq.json
CWE IDs: ["CWE-434"]
Alternative ID: GHSA-fh4q-hxrw-cjqq
Finding: F027
Auto approve: 1