TYPO3是瑞士TYPO3协会的一套免费开源的内容管理系统(框架)(CMS/CMF)。 TYPO3 Core存在安全漏洞,攻击者利用该漏洞可以通过站点配置 YAML 占位符表达式绕过对 TYPO3 核心数据的访问限制,以读取敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-23503 | 7.5 HIGH | TYPO3 vulnerable to Arbitrary Code Execution via Form Framework |
| CVE-2022-23501 | 5.9 MEDIUM | TYPO3 vulnerable to Improper Authentication in Frontend Login |
| CVE-2022-23500 | 5.9 MEDIUM | TYPO3 subject to Uncontrolled Recursion resulting in Denial of Service |
| CVE-2022-23502 | 5.4 MEDIUM | TYPO3 contains Insufficient Session Expiration after Password Reset |
No comments yet