GHSA-46fq-683f-2jwq

Suggest an improvement
Source
https://github.com/advisories/GHSA-46fq-683f-2jwq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-46fq-683f-2jwq/GHSA-46fq-683f-2jwq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-46fq-683f-2jwq
Aliases
  • CVE-2014-6289
Published
2022-05-17T04:31:54Z
Modified
2025-04-14T20:12:17Z
Severity
  • 8.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
yag and pt_extbase extensions for TYPO3 allow remote attackers to bypass access restrictions
Details

The Ajax dispatcher for Extbase in the Yet Another Gallery (yag) extension before 3.0.1 and Tools for Extbase development (pt_extbase) extension before 1.5.1 allows remote attackers to bypass access restrictions and execute arbitrary controller actions via unspecified vectors.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-04-14T19:33:24Z",
    "nvd_published_at": "2014-10-03T14:55:00Z",
    "severity": "HIGH"
}
References

Affected packages

Packagist / dl/yag

Package

Name
dl/yag
Purl
pkg:composer/dl/yag

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-46fq-683f-2jwq/GHSA-46fq-683f-2jwq.json"

Packagist / punktde/pt_extbase

Package

Name
punktde/pt_extbase
Purl
pkg:composer/punktde/pt_extbase

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-46fq-683f-2jwq/GHSA-46fq-683f-2jwq.json"