CVE-2017-6370 Information
Feb 14, 2021
cve
Description
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
http://www.securityfocus.com/bid/97071 https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: