GHSA-46fq-683f-2jwq
Dashboard / Vulnerabilities / GHSA-46fq-683f-2jwq
Summary: yag and pt_extbase extensions for TYPO3 allow remote attackers to bypass access restrictions
Details: The Ajax dispatcher for Extbase in the Yet Another Gallery (yag) extension before 3.0.1 and Tools for Extbase development (pt_extbase) extension before 1.5.1 allows remote attackers to bypass access restrictions and execute arbitrary controller actions via unspecified vectors.
References: https://nvd.nist.gov/vuln/detail/CVE-2014-6289, https://github.com/YAG-Gallery/yag/commit/4ab6ca121044d31b3822ab0c922053a9de8ee4ef, https://github.com/punktDe/pt_extbase/commit/9969635830fcf5c3222de0fd9dc0d9a05f8d6cb1, https://typo3.org/security/advisory/typo3-ext-sa-2014-005, http://typo3.org/extensions/repository/view/pt_extbase, http://typo3.org/extensions/repository/view/yag
Affected packages
Package
Name: dl/yag
Purl: pkg:composer/dl/yag
Affected ranges
Type: ECOSYSTEM
Events:
