CVE-2024-25120

Source
https://cve.org/CVERecord?id=CVE-2024-25120
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-25120.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-25120
Aliases
Published
2024-02-13T22:15:13.294Z
Modified
2026-08-12T03:51:44.037742717Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Improper Access Control of Resources Referenced by t3:// URI Scheme in TYPO3
Details

TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific t3:// URI scheme could be used to access resources outside of the users' permission scope. This encompassed files, folders, pages, and records (although only if a valid link-handling configuration was provided). Exploiting this vulnerability requires a valid backend user account. Users are advised to update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described. There are no known workarounds for this issue.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "10.0.0"
                },
                {
                    "fixed": "10.4.43"
                },
                {
                    "introduced": "9.0.0"
                },
                {
                    "fixed": "9.5.46"
                },
                {
                    "introduced": "8.0.0"
                },
                {
                    "fixed": "8.7.57"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200",
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/25xxx/CVE-2024-25120.json"
}
References

Affected packages

Git / github.com/benjaminkott/bootstrap_package

Affected ranges

Type
GIT
Repo
https://github.com/benjaminkott/bootstrap_package
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "13.0.0"
        },
        {
            "last_affected": "13.0.0"
        }
    ],
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:typo3:typo3:13.0.0:*:*:*:*:*:*:*"
}
Type
GIT
Repo
https://github.com/typo3/typo3
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "11.0.0"
        },
        {
            "fixed": "11.5.35"
        },
        {
            "introduced": "12.0.0"
        },
        {
            "fixed": "12.4.11"
        },
        {
            "introduced": "13.0.0"
        },
        {
            "last_affected": "13.0.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "cpe": [
        "cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:typo3:typo3:13.0.0:*:*:*:*:*:*:*"
    ]
}

Affected versions

13.*
13.0.0
v11.*
v11.0.0
v11.1.0
v11.2.0
v11.3.0
v11.4.0
v11.5.0
v11.5.1
v11.5.10
v11.5.11
v11.5.12
v11.5.13
v11.5.14
v11.5.15
v11.5.16
v11.5.17
v11.5.18
v11.5.19
v11.5.2
v11.5.20
v11.5.21
v11.5.22
v11.5.23
v11.5.24
v11.5.25
v11.5.26
v11.5.27
v11.5.28
v11.5.29
v11.5.3
v11.5.30
v11.5.31
v11.5.32
v11.5.33
v11.5.34
v11.5.4
v11.5.5
v11.5.6
v11.5.7
v11.5.8
v11.5.9
v12.*
v12.0.0
v12.1.0
v12.2.0
v12.3.0
v12.4.0
v12.4.1
v12.4.10
v12.4.2
v12.4.3
v12.4.4
v12.4.5
v12.4.6
v12.4.7
v12.4.8
v12.4.9
v13.*
v13.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-25120.json"