Insecure file upload In typo3/cms-core
Description
TYPO3 Unrestricted File Upload vulnerability TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 4.0.9, 4.1.7, 4.2.1 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6. 7.