GHSA-m4hw-r893-xh4g

Suggest an improvement
Source
https://github.com/advisories/GHSA-m4hw-r893-xh4g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m4hw-r893-xh4g
Aliases
  • CVE-2012-3527
Published
2022-05-17T01:43:58Z
Modified
2025-04-12T03:27:06Z
Summary
TYPO3 allows remote authenticated backend users to unserialize arbitrary objects
Details

view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."

Database specific
{
    "cwe_ids":  [
        "CWE-502"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-04-12T03:01:43Z",
    "nvd_published_at":  "2012-09-05T23:55:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / typo3/cms

Package

Name
typo3/cms
Purl
pkg:composer/typo3/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
4.5.19

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json"

Packagist / typo3/cms

Package

Name
typo3/cms
Purl
pkg:composer/typo3/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.6.0
Fixed
4.6.12

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json"

Packagist / typo3/cms

Package

Name
typo3/cms
Purl
pkg:composer/typo3/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
4.7.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json"