CVE-2017-14251

EUVD-2022-3781
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
typo3typo3
7.6.0
typo3typo3
7.6.1
typo3typo3
7.6.2
typo3typo3
7.6.3
typo3typo3
7.6.4
typo3typo3
7.6.5
typo3typo3
7.6.6
typo3typo3
7.6.7
typo3typo3
7.6.8
typo3typo3
7.6.9
typo3typo3
7.6.10
typo3typo3
7.6.11
typo3typo3
7.6.12
typo3typo3
7.6.13
typo3typo3
7.6.14
typo3typo3
7.6.15
typo3typo3
7.6.16
typo3typo3
7.6.17
typo3typo3
7.6.18
typo3typo3
7.6.19
typo3typo3
7.6.20
typo3typo3
7.6.21
typo3typo3
8.0.0
typo3typo3
8.0.1
typo3typo3
8.1.0
typo3typo3
8.1.1
typo3typo3
8.1.2
typo3typo3
8.2.0
typo3typo3
8.2.1
typo3typo3
8.3.0
typo3typo3
8.3.1
typo3typo3
8.4.0
typo3typo3
8.4.1
typo3typo3
8.5.0
typo3typo3
8.5.1
typo3typo3
8.6.0
typo3typo3
8.6.1
typo3typo3
8.7.0
typo3typo3
8.7.1
typo3typo3
8.7.2
typo3typo3
8.7.3
typo3typo3
8.7.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
typo3
trusty
dne
xenial
dne
zesty
dne