CVE-2023-38499
typo3/cms-core Information Disclosure due to Out-of-scope Site Resolution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, and 12.4.4, in multi-site scenarios, enumerating the HTTP query parameters `id` and `L` allowed out-of-scope access to rendered content in the website frontend. For instance, this allowed visitors to access content of an internal site by adding handcrafted query parameters to the URL of a site that was publicly available. TYPO3 versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, 12.4.4 fix the problem.
TYPO3 es un sistema de gestión de contenidos web de código abierto basado en PHP. A partir de la versión 9.4.0 y antes de las versiones 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, y 12.4.4 en escenarios multi-sitio, la enumeración de los parámetros de consulta HTTP "id" y "L" permitía el acceso fuera del alcance al contenido renderizado en el frontend del sitio web. Por ejemplo, esto permitía a los visitantes acceder al contenido de un sitio interno añadiendo parámetros de consulta manuales a la URL de un sitio que estaba disponible públicamente. Las versiones de TYPO3 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30 y 12.4.4 corrigen el problema.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-07-18 CVE Reserved
- 2023-07-25 CVE Published
- 2024-04-14 First Exploit
- 2024-08-26 EPSS Updated
- 2024-10-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (6)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/miguelc49/CVE-2023-38499-1 | 2024-04-14 | |
https://github.com/miguelc49/CVE-2023-38499-2 | 2024-05-06 | |
https://github.com/miguelc49/CVE-2023-38499-3 | 2024-05-06 |
URL | Date | SRC |
---|---|---|
https://github.com/TYPO3/typo3/commit/702e2debd4b28f9cdb540544565fe6a8627ccb6a | 2023-08-02 |
URL | Date | SRC |
---|---|---|
https://github.com/TYPO3/typo3/security/advisories/GHSA-jq6g-4v5m-wm9r | 2023-08-02 | |
https://typo3.org/security/advisory/typo3-core-sa-2023-003 | 2023-08-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | >= 9.4.0 < 9.5.42 Search vendor "Typo3" for product "Typo3" and version " >= 9.4.0 < 9.5.42" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | >= 10.0.0 < 10.4.39 Search vendor "Typo3" for product "Typo3" and version " >= 10.0.0 < 10.4.39" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | >= 11.0.0 < 11.5.30 Search vendor "Typo3" for product "Typo3" and version " >= 11.0.0 < 11.5.30" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | >= 12.0.0 < 12.4.4 Search vendor "Typo3" for product "Typo3" and version " >= 12.0.0 < 12.4.4" | - |
Affected
|