VDB
Sign up
MEDIUM5.0

GHSA-c7rj-92xr-wprg

Insecure Unserialize in TYPO3 Backend

Quick fix

GHSA-c7rj-92xr-wprg — typo3/cms: upgrade to the fixed version with the command below.

composer require typo3/cms:^6.2.29

Details

Failing to properly validate incoming data, the suggest wizard is susceptible to insecure unserialize. To exploit this vulnerability a valid backend user account is needed.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms
Introduced in: 6.2.0Fixed in: 6.2.29
Fixcomposer require typo3/cms:^6.2.29
Packagist/typo3/cms
Introduced in: 7.6.0Fixed in: 7.6.13
Fixcomposer require typo3/cms:^7.6.13
Packagist/typo3/cms
Introduced in: 8.0.0Fixed in: 8.4.1
Fixcomposer require typo3/cms:^8.4.1

References