← Back

CVE-2013-4320

nvd nist
Published: May 20, 2014Modified: May 6, 2026

JSON object

Loading...
5.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:N
Exploitability: 8.0 / Impact: 4.9
Source: NVD

Description

The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenticated users to create or read arbitrary files via a crafted URL.

Affected (13)

Products: Typo3: Typo3
1 product
Typo3
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Typo3
Version 6.1.1
Version 6.1.2
Version 6.1.3
Version 6.1
Configuration B
9 vulnerable
Vulnerable SoftwareAffected Versions
Typo3
Version 6.0.1
Version 6.0.2
Version 6.0.3
Version 6.0.4
Version 6.0.5
Version 6.0.6
Version 6.0.7
Version 6.0.8
Version 6.0

Related CWEs

References (2)

Timeline

No history available yet.