TYPO3
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*
- >= 9.0.0, <= 9.5.48
- >= 10.0.0, <= 10.4.47
- >= 11.0.0, <= 11.5.41
- >= 12.0.0, <= 12.4.24
- >= 13.0.0, <= 13.4.2
A vulnerability allowing open redirect or Server-Side Request Forgery (SSRF) has been identified in TYPO3 applications that use the 'TYPO3\CMS\Core\Http\Uri' component to parse externally provided URLs, such as those received via query parameters. This issue arises when the parsed URL's host is validated but the URL is subsequently used, potentially leading to unauthorized redirection or SSRF attacks.
Exploitation of this vulnerability could result in open redirect or SSRF attacks, allowing an attacker to manipulate URL redirection or make unauthorized requests to internal services, respectively.
Users are advised to update TYPO3 to versions 9.5.49 ELTS, 10.4.48 ELTS, 11.5.42 ELTS, 12.4.25 LTS, or 13.4.3 LTS, all of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.