PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTypo3 Pharstreamwrapper
APPTypo32.0.0 – 2.1.1 (excl.)3.0.0 – 3.1.1 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Deserialization
CWE
References
Related vulnerabilities
CVE-2019-11831CRITICAL9.8PL ✓same product
Path Traversal w PharStreamWrapper pozwala ominąć ochronę przed deserializacją
CVE-2020-15086CRITICAL9.8PL ✓same vendor
RCE przez fałszowanie sumy kontrolnej w rozszerzeniu TYPO3 mediace
CVE-2011-3583CRITICAL9.8PL ✓same vendor
SQL Injection w TYPO3 Core przez niepoprawne prepared statements
CVE-2011-4628CRITICAL9.8PL ✓same vendor
TYPO3: Ominięcie mechanizmu uwierzytelniania w panelu administracyjnym
CVE-2026-6553HIGH7.3same vendor
Changing backend users' passwords via the user settings module results in storing the cleartext password in th...