CVE-2013-7081 Information

Description

The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31 4.7.0 through 4.7.16 6.0.0 through 6.0.11 and 6.1.0 through 6.1.6 allows remote authenticated editors to generate arbitrary HMAC signatures and bypass intended access restrictions via unspecified vectors.

Reference

http://seclists.org/oss-sec/2013/q4/473 http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004/ http://www.debian.org/security/2014/dsa-2834

Share on: