The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execution. In versions later than 1.2.2, this can result in Denial of Service, since the web space can be filled up with arbitrary files.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2635 | The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execution. In versions later than 1.2.2, this can result in Denial of Service, since the web space can be filled up with arbitrary files. |
Github GHSA |
GHSA-5pww-3mfc-g8vr | slub_events for Typo3 Arbitrary File Upload |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:17:41.123Z
Reserved: 2019-09-22T00:00:00
Link: CVE-2019-16700
No data.
Status : Modified
Published: 2019-10-16T19:15:15.927
Modified: 2024-11-21T04:31:00.450
Link: CVE-2019-16700
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA