MEDIUM6.5
GHSA-772m-43f3-hmf8
TYPO3 Broken Access Control in Localization Handling
Quick fix
GHSA-772m-43f3-hmf8 — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^8.7.23Details
It has been discovered that backend users having limited access to specific languages are capable of modifying and creating pages in the default language which actually should be disallowed. A valid backend user account is needed in order to exploit this vulnerability.
Are you affected?
Enter the version of the package you're using.