CVE-2017-14251

Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
typo3typo3
7.6.0
typo3typo3
7.6.1
typo3typo3
7.6.2
typo3typo3
7.6.3
typo3typo3
7.6.4
typo3typo3
7.6.5
typo3typo3
7.6.6
typo3typo3
7.6.7
typo3typo3
7.6.8
typo3typo3
7.6.9
typo3typo3
7.6.10
typo3typo3
7.6.11
typo3typo3
7.6.12
typo3typo3
7.6.13
typo3typo3
7.6.14
typo3typo3
7.6.15
typo3typo3
7.6.16
typo3typo3
7.6.17
typo3typo3
7.6.18
typo3typo3
7.6.19
typo3typo3
7.6.20
typo3typo3
7.6.21
typo3typo3
8.0.0
typo3typo3
8.0.1
typo3typo3
8.1.0
typo3typo3
8.1.1
typo3typo3
8.1.2
typo3typo3
8.2.0
typo3typo3
8.2.1
typo3typo3
8.3.0
typo3typo3
8.3.1
typo3typo3
8.4.0
typo3typo3
8.4.1
typo3typo3
8.5.0
typo3typo3
8.5.1
typo3typo3
8.6.0
typo3typo3
8.6.1
typo3typo3
8.7.0
typo3typo3
8.7.1
typo3typo3
8.7.2
typo3typo3
8.7.3
typo3typo3
8.7.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
typo3
zesty
dne
xenial
dne
trusty
dne