CVE-2011-4904

MEDIUM6.5EPSS 0.24%

Typo3 Improper Access Control

Published: 4/22/2022Modified: 1/12/2024
Also known as:GHSA-qf79-34j4-54m6

Description

TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (4)