CVE-2024-25120
MEDIUM4.3EPSS 0.19%TYPO3 vulnerable to Improper Access Control of Resources Referenced by t3:// URI Scheme
Description
### Problem The TYPO3-specific [`t3://` URI scheme](https://docs.typo3.org/m/typo3/reference-typoscript/main/en-us/Functions/Typolink.html#resource-references) could be used to access resources outside of the users' permission scope. This encompassed files, folders, pages, and records (although only if a valid link-handling configuration was provided). Exploiting this vulnerability requires a valid backend user account. ### Solution Update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described. ### Credits Thanks to Richie Lee who reported this issue and to TYPO3 core & security team member Benjamin Franzke who fixed the issue. ### References * [TYPO3-CORE-SA-2024-005](https://typo3.org/security/advisory/typo3-core-sa-2024-005)
Affected packages (1)
- Packagist/typo3/cms-core>= 8.0.0, < 8.7.57
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
References (8)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2024-25120
- PATCHhttps://github.com/TYPO3/typo3
- WEBhttps://docs.typo3.org/m/typo3/reference-typoscript/main/en-us/Functions/Typolink.html#resource-references
- WEBhttps://github.com/TYPO3/typo3/commit/2de87ff113ba24333ab7cbb8078588743f8958d6
- WEBhttps://github.com/TYPO3/typo3/commit/33f4d279b82bca0a509227a17065244c6156e68f
- WEBhttps://github.com/TYPO3/typo3/commit/ae0dfc4c058a90c10eedb3f49cfaf33164d21cdd
- WEBhttps://github.com/TYPO3/typo3/security/advisories/GHSA-wf85-8hx9-gj7c
- WEBhttps://typo3.org/security/advisory/typo3-core-sa-2024-005