Deserialization of Untrusted Data in TYPO3 - CVE-2020-11066
Published: May 15, 2020
TYPO3
TYPO3
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can pass specially crafted data to the application and trigger deletion of arbitrary directory in file system or trigger message submission via email using identity of web site.