CVE-2023-30451
Path Traversal in TYPO3 File Abstraction Layer Storages
5.5
MEDIUM
CVSS 3.1
EPSS 1.2%
Description
In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with ../../../ in data[sys_file_storage]*[data][sDEF][lDEF][basePath][vDEF].
How to fix CVE-2023-30451
To remediate CVE-2023-30451, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 8.7.57 or later
Is CVE-2023-30451 being exploited?
Low — EPSS is 1.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 11.5.24, <= 11.5.24
- >= 8.0.0, < 8.7.57
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N |