Information disclosure in TYPO3 - CVE-2012-3529

 

Information disclosure in TYPO3 - CVE-2012-3529

Published: September 6, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43627
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2012-3529
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: TYPO3
Affected software:
TYPO3

Detailed vulnerability description

The vulnerability allows a remote #AU# to gain access to sensitive information.

The configuration module in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to obtain the encryption key via unspecified vectors.


How to mitigate CVE-2012-3529

Install update from vendor's website.

Sources