CVE-2024-22188

EUVD-2024-0525
TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
typo3typo3
8.0.0 ≤
𝑥
< 8.7.57
typo3typo3
9.0.0 ≤
𝑥
< 9.5.46
typo3typo3
10.0.0 ≤
𝑥
< 10.4.43
typo3typo3
11.0.0 ≤
𝑥
< 11.5.35
typo3typo3
12.0.0 ≤
𝑥
< 12.4.11
typo3typo3
13.0.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
typo3typo3
8.0.0 ≤
𝑥
≤ 8.7.56
ADP
typo3typo3
9.0.0 ≤
𝑥
≤ 9.5.45
ADP
typo3typo3
10.0.0 ≤
𝑥
≤ 10.4.42
ADP
typo3typo3
11.0.0 ≤
𝑥
≤ 11.5.34
ADP
typo3typo3
12.0.0 ≤
𝑥
≤ 12.4.10
ADP