TYPO3 CMS
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*
- >= 9.0.0, <= 9.5.54
- >= 10.0.0, <= 10.4.53
- >= 11.0.0, <= 11.5.47
- >= 12.0.0, <= 12.4.36
- >= 13.0.0, <= 13.4.17
A vulnerability allowing information disclosure has been identified in TYPO3 CMS versions 9.0.0 prior to 9.5.54, 10.0.0 prior to 10.4.53, 11.0.0 prior to 11.5.47, 12.0.0 prior to 12.4.36, and 13.0.0 prior to 13.4.17. This vulnerability arises from error messages in the File Abstraction Layer that unintentionally reveal full file paths. The issue occurs during certain low-level file-system operations that fail, disclosing sensitive information to backend users.
Exploitation of this vulnerability could lead to unauthorized disclosure of file system paths, potentially allowing for further attacks that rely on knowledge of the file system structure.
Users are advised to update to TYPO3 versions 9.5.55 ELTS, 10.4.54 ELTS, 11.5.48 ELTS, 12.4.37 LTS, or 13.4.18 LTS, all of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.