Description
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3136 | TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields. |
Github GHSA |
GHSA-87hc-phmj-rhgh | TYPO3 Information Disclosure Vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T15:25:49.256Z
Reserved: 2017-02-28T00:00:00.000Z
Link: CVE-2017-6370
No data.
Status : Deferred
Published: 2017-03-17T17:59:00.157
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-6370
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA