CVE-2019-19848

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
17/12/2019
Last modified:
23/12/2019

Description

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 8.7.30 (excluding)
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 9.0.0 (including) 9.5.12 (excluding)
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 10.0.0 (including) 10.2.2 (excluding)