HomeTypo3CVE-2022-23504

CVE-2022-23504

MEDIUM
5.7CVSS
Published: 2022-12-14
Updated: 2024-11-21
AI Analysis

Description

TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are subject to Sensitive Information Disclosure. Due to the lack of handling user-submitted YAML placeholder expressions in the site configuration backend module, attackers could expose sensitive internal information, such as system configuration or HTTP request messages of other website visitors. A valid backend user account having administrator privileges is needed to exploit this vulnerability. This issue has been patched in versions 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L
Attack Vector
network
Complexity
low
Privileges
high
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
low
Availability
low
Weaknesses
CWE-200CWE-917CWE-917

Metadata

Primary Vendor
TYPO3
Published
12/14/2022
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

typo3 : typo3typo3 : typo3typo3 : typo3typo3 : typo3

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2022-23504 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com