CVE-2010-3663
HIGH8.8EPSS 3.0%TYPO3 Arbitrary Code Execution vulnerability on the backend
發布日:2022/4/21修改日:2024/2/6
描述
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.
受影響套件(1)
- Packagist/typo3/cms-backendfrom 0, < 4.1.14
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |