CVE-2019-16700 Information
Feb 14, 2021
cve
Description
The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below this results in Remote Code Execution. In versions later than 1.2.2 this can result in Denial of Service since the web space can be filled up with arbitrary files.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://extensions.typo3.org/extension/slub_events https://typo3.org/security/advisory/typo3-ext-sa-2019-017/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: