TYPO3 vulnerable to Insecure Unserialize via Content Editing Wizards component
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Aug 29, 2023
Package
Affected versions
>= 4.5.0, <= 4.5.31
>= 4.7.0, <= 4.7.16
>= 6.0.0, <= 6.0.11
>= 6.1.0, <= 6.1.6
Patched versions
4.5.32
4.7.17
6.0.12
6.1.7
Description
Published by the National Vulnerability Database
Dec 23, 2013
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Aug 29, 2023
Last updated
Aug 29, 2023
The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated backend users to unserialize arbitrary PHP objects, delete arbitrary files, and possibly have other unspecified impacts via an unspecified parameter, related to a "missing signature."
References