logo

CVE-2017-6370 typo3/cms

Package

Manager: composer
Name: typo3/cms
Vulnerable Version: =7.6.15

Severity

Level: Medium

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00112 pctl0.30375

Details

TYPO3 Information Disclosure Vulnerability TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.

Metadata

Created: 2022-05-13T01:46:32Z
Modified: 2024-04-25T21:29:41Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-87hc-phmj-rhgh/GHSA-87hc-phmj-rhgh.json
CWE IDs: ["CWE-319"]
Alternative ID: GHSA-87hc-phmj-rhgh
Finding: F017
Auto approve: 1