TYPO3 Faceted Search
cpe:2.3:a:kennziffer:ke_search:*:*:*:*:*:*:*
- 7.0.0
- 6.0.0 - 6.6.0
- <= 5.6.1
A vulnerability in the TYPO3 extension 'Faceted Search' (ke_search) allows for XML External Entity (XXE) injection. The issue arises because the OOXML parser in the file indexer does not disable external entity resolution. This flaw enables a crafted xlsx or pptx document placed in an indexed directory to read local files or make outbound HTTP requests, with the retrieved content being added to the search index. Additionally, the file indexer's directory path normalization is inadequate, permitting path traversal exploitation to access arbitrary server files.
Exploitation of this vulnerability could lead to unauthorized reading of local files or execution of outbound HTTP requests, with potentially sensitive content being indexed and made searchable.
Users are advised to update to version 7.0.1, 6.6.1, or 5.6.2, available through the TYPO3 Extension Manager, Packagist, or directly from the TYPO3 Extensions Repository.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.