HIGH
GHSA-55g3-fjwm-w2c8
TYPO3 Color Picker Wizard component allows remote authenticated editors to execute arbitrary PHP code
Quick fix
GHSA-55g3-fjwm-w2c8 — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^4.5.34Details
The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authenticated editors to execute arbitrary PHP code via a serialized PHP object.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2014-3942[ADVISORY]
- https://github.com/TYPO3/typo3[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2014-001[WEB]
- http://lists.opensuse.org/opensuse-updates/2014-06/msg00037.html[WEB]
- http://www.debian.org/security/2014/dsa-2942[WEB]
- http://www.openwall.com/lists/oss-security/2014/06/03/2[WEB]