CVE-2017-14251

Source
https://cve.org/CVERecord?id=CVE-2017-14251
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14251.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-14251
Aliases
Published
2017-09-11T09:29:00.467Z
Modified
2026-04-10T03:57:07.667529Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.

References

Affected packages

Git / github.com/typo3/typo3.cms

Affected ranges

Type
GIT
Repo
https://github.com/typo3/typo3.cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.7"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.8"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.9"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.10"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.11"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.12"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.13"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.14"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.15"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.16"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.17"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.18"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.19"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.20"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.6.21"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.0.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.0.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.1.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.1.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.1.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.2.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.2.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.3.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.3.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.4.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.4.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.5.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.5.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.6.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.6.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.7.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.7.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.7.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.7.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.7.4"
        }
    ]
}

Affected versions

6.*
6.2.0
6.2.1
6.2.2
6.2.3
7.*
7.0.0
7.1.0
7.2.0
7.3.0
7.4.0
7.5.0
7.6.0
7.6.1
7.6.10
7.6.11
7.6.12
7.6.13
7.6.14
7.6.15
7.6.16
7.6.17
7.6.18
7.6.19
7.6.2
7.6.20
7.6.21
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.6.9
8.*
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.2.1
8.3.0
8.3.1
8.4.0
8.4.1
8.5.0
8.5.1
8.6.0
8.6.1
8.7.0
8.7.1
8.7.2
8.7.3
8.7.4
Other
TYPO3_6-1-0rc1
TYPO3_6-2-0
TYPO3_6-2-0alpha1
TYPO3_6-2-0alpha2
TYPO3_6-2-0alpha3
TYPO3_6-2-0beta1
TYPO3_6-2-0beta2
TYPO3_6-2-0beta3
TYPO3_6-2-0beta4
TYPO3_6-2-0beta5
TYPO3_6-2-0beta6
TYPO3_6-2-0beta7
TYPO3_6-2-0rc1
TYPO3_6-2-0rc2
TYPO3_6-2-1
TYPO3_6-2-2
TYPO3_6-2-3
TYPO3_7-0-0
TYPO3_7-1-0
TYPO3_7-2-0
TYPO3_7-3-0
TYPO3_7-4-0
TYPO3_7-5-0
TYPO3_7-6-0
TYPO3_7-6-1
TYPO3_7-6-10
TYPO3_7-6-11
TYPO3_7-6-12
TYPO3_7-6-13
TYPO3_7-6-14
TYPO3_7-6-15
TYPO3_7-6-16
TYPO3_7-6-17
TYPO3_7-6-18
TYPO3_7-6-19
TYPO3_7-6-2
TYPO3_7-6-20
TYPO3_7-6-21
TYPO3_7-6-3
TYPO3_7-6-4
TYPO3_7-6-5
TYPO3_7-6-6
TYPO3_7-6-7
TYPO3_7-6-8
TYPO3_7-6-9
TYPO3_8-0-0
TYPO3_8-0-1
TYPO3_8-1-0
TYPO3_8-1-1
TYPO3_8-1-2
TYPO3_8-2-0
TYPO3_8-2-1
TYPO3_8-3-0
TYPO3_8-3-1
TYPO3_8-4-0
TYPO3_8-4-1
TYPO3_8-5-0
TYPO3_8-5-1
TYPO3_8-6-0
TYPO3_8-6-1
TYPO3_8-7-0
TYPO3_8-7-1
TYPO3_8-7-2
TYPO3_8-7-3
TYPO3_8-7-4
v7.*
v7.6.20
v7.6.21
v8.*
v8.7.3
v8.7.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14251.json"