In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of third party components, this can lead to remote code execution. A valid backend user account is needed to exploit this vulnerability. This has been fixed in 9.5.17 and 10.4.2.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T11:21:14.623Z

Reserved: 2020-03-30T00:00:00

Link: CVE-2020-11067

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-14T00:15:11.400

Modified: 2024-11-21T04:56:43.023

Link: CVE-2020-11067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.