GHSA-m4hw-r893-xh4g
Dashboard / Vulnerabilities / GHSA-m4hw-r893-xh4g
Summary: TYPO3 allows remote authenticated backend users to unserialize arbitrary objects
Details: view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."
References: https://nvd.nist.gov/vuln/detail/CVE-2012-3527, https://exchange.xforce.ibmcloud.com/vulnerabilities/77791, https://github.com/TYPO3/typo3, https://web.archive.org/web/20120817233148/http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004, http://www.debian.org/security/2012/dsa-2537, http://www.openwall.com/lists/oss-security/2012/08/22/8
Affected packages
Package
Name: typo3/cms
Purl: pkg:composer/typo3/cms
Affected ranges
Type: ECOSYSTEM
Events:
