CVE-2016-5091

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
23/01/2017
Last modified:
20/04/2025

Description

Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 6.2.23 (including)
cpe:2.3:a:typo3:typo3:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.3.1:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.6.1:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.6.3:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.6.4:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:7.6.5:*:*:*:*:*:*:*