TYPO3 allows remote authenticated backend users to unserialize arbitrary objects
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2025
Package
Affected versions
>= 4.5.0, < 4.5.19
>= 4.6.0, < 4.6.12
>= 4.7.0, < 4.7.4
Patched versions
4.5.19
4.6.12
4.7.4
Description
Published by the National Vulnerability Database
Sep 5, 2012
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Apr 12, 2025
Last updated
Apr 12, 2025
view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."
References