TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.
{
"versions": [
{
"introduced": "11.0.0"
},
{
"fixed": "11.5.35"
},
{
"introduced": "12.0.0"
},
{
"fixed": "12.4.11"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.0"
}
]
}[
{
"events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.7.57"
}
]
},
{
"events": [
{
"introduced": "9.0.0"
},
{
"fixed": "9.5.46"
}
]
},
{
"events": [
{
"introduced": "10.0.0"
},
{
"fixed": "10.4.43"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-22188.json"