CVE-2024-22188 Information
Mar 07, 2024
cve
Description
TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS 9.5.46 ELTS 10.4.43 ELTS 11.5.35 LTS 12.4.11 LTS and 13.0.1.
Reference
https://typo3.org/help/security-advisories https://typo3.org/security/advisory/typo3-core-sa-2024-002 https://github.com/TYPO3/typo3/security/advisories/GHSA-5w2h-59j3-8x5w
Share on: