TYPO3
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*
- >= 10.0.0, <= 10.4.54
- >= 11.0.0, <= 11.5.48
- >= 12.0.0, <= 12.4.40
- >= 13.0.0, <= 13.4.22
- >= 14.0.0, <= 14.0.1
A broken access control vulnerability has been identified in the TYPO3 CMS redirects module, affecting versions 10.0.0 prior to 10.4.54, 11.0.0 prior to 11.5.48, 12.0.0 prior to 12.4.40, 13.0.0 prior to 13.4.22, and 14.0.0 through 14.0.1. Backend users with write permission on the sys_redirect table could read, create, and modify any redirect record without restrictions based on their file or web mounts. This vulnerability allowed the insertion or alteration of redirects to arbitrary URLs, potentially facilitating phishing or other malicious redirect activities.
Exploitation of this vulnerability could lead to unauthorized access and modification of redirect records, allowing for the creation of malicious redirects that could be used for phishing or other harmful purposes.
To reproduce this vulnerability, a backend user must have access to the redirects module and write permission on the sys_redirect table. Once these conditions are met, the user can read, create, and modify redirect records without any restrictions. This can be done by navigating to the redirects module and managing the sys_redirect records directly.
Users are advised to update TYPO3 to versions 10.4.55 ELTS, 11.5.49 ELTS, 12.4.41 LTS, 13.4.23 LTS, or 14.0.2, all of which include the necessary fix.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.