← Back

CVE-2024-34358

nvd nist
Published: May 14, 2024Modified: Sep 3, 2025

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature on the `frame` HTTP query parameter (e.g. `/index.php?eID=tx_cms_showpic?file=3&...&frame=12345`). This allows adversaries to instruct the system to produce an arbitrary number of thumbnail images on the server side. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.

Affected (5)

Products: Typo3: Typo3
1 product
Typo3
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Typo3
From 10.0.0 to 10.4.45
From 11.0.0 to 11.5.37
From 12.0.0 to 12.4.15
From 13.0.0 to 13.1.1
From 9.0.0 to 9.5.48

References (10)

Source: security-advisories@github.com
MitigationVendor Advisory
Source: security-advisories@github.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.