漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
TYPO3 CMS - Broken Access Control in Media Module
Vulnerability Description
Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such as log files. This issue affects TYPO3 CMS versions 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
TYPO3 CMS 路径遍历漏洞
Vulnerability Description
TYPO3 CMS是TYPO3开源的一个内容管理系统。 TYPO3 CMS 11.0.0至11.5.50版本、12.0.0至12.4.45版本、13.0.0至13.4.30版本和14.0.0至14.3.2版本存在路径遍历漏洞,该漏洞源于具有文件下载权限的后端用户能够通过媒体模块从文件抽象层的回退存储下载文件,由于回退存储相对于服务器文档根目录解析路径,可能暴露敏感文件如日志文件。
CVSS Information
N/A
Vulnerability Type
N/A