VDB
Sign up
HIGH

GHSA-4h9j-f98m-p4hg

TYPO3 PHP remote file inclusion vulnerability

Quick fix

GHSA-4h9j-f98m-p4hg — typo3/cms: upgrade to the fixed version with the command below.

composer require typo3/cms:^4.3.3

Details

PHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x before 4.3.3 allows remote attackers to execute arbitrary PHP code via a URL in an input field associated with the className variable.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms
Introduced in: 4.3.0Fixed in: 4.3.3
Fixcomposer require typo3/cms:^4.3.3

References