TYPO3 Arbitrary Code Execution
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 25, 2024
Package
Affected versions
>= 7.6.0, < 7.6.22
>= 8.0.0, < 8.7.5
Patched versions
7.6.22
8.7.5
Description
Published by the National Vulnerability Database
Sep 11, 2017
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Apr 25, 2024
Last updated
Apr 25, 2024
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.
References