GHSA-5fj8-wh3g-qvq2

Suggest an improvement
Source
https://github.com/advisories/GHSA-5fj8-wh3g-qvq2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5fj8-wh3g-qvq2/GHSA-5fj8-wh3g-qvq2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5fj8-wh3g-qvq2
Aliases
  • CVE-2013-7080
Published
2022-05-17T04:54:37Z
Modified
2023-11-08T03:57:27.828722Z
Summary
TYPO3 is vulnerable to Mass Assignment in the Extension table administration library
Details

The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."

Database specific
{
    "nvd_published_at": "2013-12-23T23:55:00Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-08-29T19:02:14Z"
}
References

Affected packages

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
4.5.31

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.6.0
Fixed
4.7.16

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.0.11