CVE-2024-34537

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/10/2024
Last modified:
03/09/2025

Description

TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 10.0.0 (including) 10.4.46 (excluding)
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 11.0.0 (including) 11.5.40 (excluding)
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 12.0.0 (including) 12.4.21 (excluding)
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 13.0.0 (including) 13.3.1 (excluding)