CVE-2014-8328

The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 54%
VendorProductVersion
dynamic_content_elements_projectdynamic_content_elements
0.7.0 ≤
𝑥
≤ 0.7.5
dynamic_content_elements_projectdynamic_content_elements
0.8.0 ≤
𝑥
≤ 0.8.6
dynamic_content_elements_projectdynamic_content_elements
0.9.0 ≤
𝑥
≤ 0.9.4
dynamic_content_elements_projectdynamic_content_elements
0.10.0 ≤
𝑥
≤ 0.10.2
dynamic_content_elements_projectdynamic_content_elements
0.11.0 ≤
𝑥
< 0.11.5
𝑥
= Vulnerable software versions