TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1.
History

Thu, 31 Oct 2024 16:45:00 +0000


Mon, 28 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Oct 2024 13:30:00 +0000

Type Values Removed Values Added
Description TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-28T00:00:00

Updated: 2024-10-31T16:35:30.213028

Reserved: 2024-05-06T00:00:00

Link: CVE-2024-34537

cve-icon Vulnrichment

Updated: 2024-10-28T16:14:22.018Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-28T14:15:04.740

Modified: 2024-10-31T17:15:12.903

Link: CVE-2024-34537

cve-icon Redhat

No data.