Exposure of Sensitive Information to an Unauthorized Actor Affecting typo3/cms-backend package, versions <11.5.35>=12.0.0, <12.4.11>=13.0.0, <13.0.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Mature
EPSS
0.05% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-TYPO3CMSBACKEND-6245722
  • published14 Feb 2024
  • disclosed13 Feb 2024
  • creditRichie Lee

Introduced: 13 Feb 2024

CVE-2024-25120  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade typo3/cms-backend to version 11.5.35, 12.4.11, 13.0.1 or higher.

Overview

Affected versions of this package are vulnerable to Exposure of Sensitive Information to an Unauthorized Actor due to the TYPO3-specific t3:// URI scheme, which could be used to access resources outside of the users' permission scope, including files, folders, pages, and records (although only if a valid link-handling configuration was provided). An attacker can exploit this vulnerability by leveraging a valid backend user account.

CVSS Scores

version 3.1