MEDIUM6.5
GHSA-4rpv-g4gq-rh4m
TYPO3 vulnerable to Information Disclosure via Content Editing Wizards component
Quick fix
GHSA-4rpv-g4gq-rh4m — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^4.5.32Details
The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 does not check permissions, which allows remote authenticated editors to read arbitrary TYPO3 table columns via unspecified parameters.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-7073[ADVISORY]
- https://github.com/TYPO3/typo3[PACKAGE]
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00028.html[WEB]
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00083.html[WEB]
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00106.html[WEB]
- http://seclists.org/oss-sec/2013/q4/473[WEB]
- http://seclists.org/oss-sec/2013/q4/487[WEB]
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004[WEB]
- http://www.debian.org/security/2014/dsa-2834[WEB]