Impact
The Mask extension fails to validate a client‑supplied template element key before using it to build file paths for saving and deleting template files. As a result, a key containing path traversal sequences can be used to create or delete .html files outside the intended template directory. This allows an attacker to inject arbitrary files or remove critical files, potentially compromising the integrity of the website and the underlying CMS.
Affected Systems
The vulnerability exists in the TYPO3 CMS extension named “Mask”. No specific version information is provided in the advisory, so all installations of the Mask extension that have not been patched are potentially affected.
Risk and Exploitability
The advisory assigns a CVSS score of 6, indicating moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The vulnerability requires an authenticated backend user with access to the Mask module; no additional privileges are needed to manipulate files. Once such a user is present, the attack can be carried out trivially by supplying a crafted key. Given the moderate CVSS and the fact that it does not require remote access, the immediate threat is limited to sites where privileged users may be compromised.
OpenCVE Enrichment