SB2013122408 - Input validation error in TYPO3



SB2013122408 - Input validation error in TYPO3

Published: December 24, 2013 Updated: August 10, 2020

Security Bulletin ID SB2013122408
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2013-7080)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."


Remediation

Install update from vendor's website.