TYPO3 Unrestricted File Upload vulnerability
Moderate severity
GitHub Reviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Feb 9, 2024
Package
Affected versions
>= 4.0.0, < 4.0.9
>= 4.1.0, < 4.1.7
>= 4.2.0, < 4.2.1
Patched versions
4.0.9
4.1.7
4.2.1
Description
Published by the National Vulnerability Database
Jun 16, 2008
Published to the GitHub Advisory Database
May 1, 2022
Reviewed
Feb 9, 2024
Last updated
Feb 9, 2024
TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.
References