CVE-2017-6370 – typo3/cms
Package
Manager: composer
Name: typo3/cms
Vulnerable Version: =7.6.15
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00112 pctl0.30375
Details
TYPO3 Information Disclosure Vulnerability TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
Metadata
Created: 2022-05-13T01:46:32Z
Modified: 2024-04-25T21:29:41Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-87hc-phmj-rhgh/GHSA-87hc-phmj-rhgh.json
CWE IDs: ["CWE-319"]
Alternative ID: GHSA-87hc-phmj-rhgh
Finding: F017
Auto approve: 1