Permissions, Privileges, and Access Controls in TYPO3 - CVE-2013-7073

 

Permissions, Privileges, and Access Controls in TYPO3 - CVE-2013-7073

Published: December 24, 2013 / Updated: August 10, 2020


Vulnerability identifier: #VU42210
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2013-7073
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: TYPO3
Affected software:
TYPO3

Detailed vulnerability description

The vulnerability allows a remote #AU# to gain access to sensitive information.

The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 does not check permissions, which allows remote authenticated editors to read arbitrary TYPO3 table columns via unspecified parameters.


How to mitigate CVE-2013-7073

Install update from vendor's website.

Sources