CVE-2024-22188
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
05/03/2024
Last modified:
15/09/2025
Description
TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | 8.0.0 (including) | 8.7.57 (excluding) |
| cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | 9.0.0 (including) | 9.5.46 (excluding) |
| cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | 10.0.0 (including) | 10.4.43 (excluding) |
| cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | 11.0.0 (including) | 11.5.35 (excluding) |
| cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | 12.0.0 (including) | 12.4.11 (excluding) |
| cpe:2.3:a:typo3:typo3:13.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/TYPO3/typo3/security/advisories/GHSA-5w2h-59j3-8x5w
- https://typo3.org/security/advisory/typo3-core-sa-2024-002
- https://github.com/TYPO3/typo3/security/advisories/GHSA-5w2h-59j3-8x5w
- https://typo3.org/help/security-advisories
- https://typo3.org/security/advisory/typo3-core-sa-2024-002



