CVE-2020-11067

HIGH8.8EPSS 1.2%

Insecure Deserialization in Backend User Settings in TYPO3 CMS

Published: 5/13/2020Modified: 3/13/2026
Also known as:GHSA-2wj9-434x-9hvpBIT-typo3-2020-11067

Description

It has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of 3rd party components this can lead to remote code execution. A valid backend user account is needed to exploit this vulnerability. Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described. ### References * https://typo3.org/security/advisory/typo3-core-sa-2020-005

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (5)