Denial of service in TYPO3 - #VU16759
Published: December 28, 2018
TYPO3
Detailed vulnerability description
The vulnerability exists in TYPO3’s built-in record registration functionality (aka “basic shopping cart”) using recs URL parameters due to improper ensurement that anonymous user sessions are valid. A remote attacker can create an arbitrary amount of individual session-data records in the database and cause the service to crash.