CVE-2013-7073

EUVD-2022-2443
The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 does not check permissions, which allows remote authenticated editors to read arbitrary TYPO3 table columns via unspecified parameters.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
Affected Products (NVD)
VendorProductVersion
typo3typo3
4.5.0
typo3typo3
4.5.1
typo3typo3
4.5.2
typo3typo3
4.5.3
typo3typo3
4.5.4
typo3typo3
4.5.5
typo3typo3
4.5.6
typo3typo3
4.5.7
typo3typo3
4.5.8
typo3typo3
4.5.9
typo3typo3
4.5.10
typo3typo3
4.5.11
typo3typo3
4.5.12
typo3typo3
4.5.13
typo3typo3
4.5.14
typo3typo3
4.5.15
typo3typo3
4.5.16
typo3typo3
4.5.17
typo3typo3
4.5.18
typo3typo3
4.5.19
typo3typo3
4.5.20
typo3typo3
4.5.21
typo3typo3
4.5.22
typo3typo3
4.5.23
typo3typo3
4.5.24
typo3typo3
4.5.25
typo3typo3
4.5.26
typo3typo3
4.5.27
typo3typo3
4.5.28
typo3typo3
4.5.29
typo3typo3
4.5.30
typo3typo3
4.5.31
typo3typo3
6.1
typo3typo3
6.1.1
typo3typo3
6.1.2
typo3typo3
6.1.3
typo3typo3
6.1.4
typo3typo3
6.1.5
typo3typo3
6.1.6
typo3typo3
6.0
typo3typo3
6.0.1
typo3typo3
6.0.2
typo3typo3
6.0.3
typo3typo3
6.0.4
typo3typo3
6.0.5
typo3typo3
6.0.6
typo3typo3
6.0.7
typo3typo3
6.0.8
typo3typo3
6.0.9
typo3typo3
6.0.10
typo3typo3
6.0.11
typo3typo3
4.7.0
typo3typo3
4.7.1
typo3typo3
4.7.2
typo3typo3
4.7.3
typo3typo3
4.7.4
typo3typo3
4.7.5
typo3typo3
4.7.6
typo3typo3
4.7.7
typo3typo3
4.7.8
typo3typo3
4.7.9
typo3typo3
4.7.10
typo3typo3
4.7.11
typo3typo3
4.7.12
typo3typo3
4.7.13
typo3typo3
4.7.14
typo3typo3
4.7.15
typo3typo3
4.7.16
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
typo3-src
lucid
ignored
precise
ignored
quantal
ignored
raring
Fixed 4.5.19+dfsg1-5+wheezy2build0.13.04.1
released
saucy
ignored
trusty
dne
utopic
not-affected
vivid
not-affected
wily
dne
xenial
dne
yakkety
dne
zesty
dne
Common Weakness Enumeration