Exposure of Sensitive Information to an Unauthorized Actor Affecting typo3/cms-backend package, versions <11.5.35>=12.0.0, <12.4.11>=13.0.0, <13.0.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.19% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Exposure of Sensitive Information to an Unauthorized Actor vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-TYPO3CMSBACKEND-6245722
  • published14 Feb 2024
  • disclosed13 Feb 2024
  • creditRichie Lee

Introduced: 13 Feb 2024

CVE-2024-25120  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade typo3/cms-backend to version 11.5.35, 12.4.11, 13.0.1 or higher.

Overview

Affected versions of this package are vulnerable to Exposure of Sensitive Information to an Unauthorized Actor due to the TYPO3-specific t3:// URI scheme, which could be used to access resources outside of the users' permission scope, including files, folders, pages, and records (although only if a valid link-handling configuration was provided). An attacker can exploit this vulnerability by leveraging a valid backend user account.

CVSS Base Scores

version 3.1