CVE-2014-8328

EUVD-2022-5281
The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 54%
Affected Products (NVD)
VendorProductVersion
dynamic_content_elements_projectdynamic_content_elements
0.7.0 ≤
𝑥
≤ 0.7.5
dynamic_content_elements_projectdynamic_content_elements
0.8.0 ≤
𝑥
≤ 0.8.6
dynamic_content_elements_projectdynamic_content_elements
0.9.0 ≤
𝑥
≤ 0.9.4
dynamic_content_elements_projectdynamic_content_elements
0.10.0 ≤
𝑥
≤ 0.10.2
dynamic_content_elements_projectdynamic_content_elements
0.11.0 ≤
𝑥
< 0.11.5
𝑥
= Vulnerable software versions