#VU23643 Path traversal in TYPO3
Published: December 17, 2019
TYPO3
TYPO3
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within Extension Manager during extraction of manual uploaded ZIP archives. A remote attacker can trick an administrator into uploading a specially crafted zip file that contains directory traversal characters in its name and overwrite arbitrary files on the system.