TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, the export functionality fails to limit the result set to allowed columns of a particular database table. This way, authenticated users can export internal details of database tables they already have access to. TYPO3 versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, 11.5.11 fix the problem described above. In order to address this issue, access to mentioned export functionality is completely denied for regular backend users.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-06-14T20:40:22
Updated: 2024-08-03T07:03:40.293Z
Reserved: 2022-05-18T00:00:00
Link: CVE-2022-31046
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-06-14T21:15:15.987
Modified: 2024-11-21T07:03:46.810
Link: CVE-2022-31046
Redhat
No data.