CVE-2012-3527
MEDIUM severity · CVSS 4.6 · Insecure deserialization
4.6CVSS MEDIUM
Summary
view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."
Impact & exploitability
Attack vectorNetwork
Attack complexityHigh
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)2%
AV:N/AC:H/Au:S/C:P/I:P/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004/Advisory
- http://osvdb.org/84773
- http://secunia.com/advisories/50287
- http://www.debian.org/security/2012/dsa-2537Advisory
- http://www.openwall.com/lists/oss-security/2012/08/22/8
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77791Advisory