CRITICAL🇵🇱 Wersja polska

CVE-2020-15086

CVSS 9.8v3.1pub. 2020-07-29upd. 2024-11-21

In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. The allows to inject arbitrary data having a valid cryptographic message authentication code and can lead to remote code execution. To successfully exploit this vulnerability, an attacker must have access to at least one `Extbase` plugin or module action in a TYPO3 installation. This is fixed in version 7.6.5 of the "mediace" extension for TYPO3.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Typo3 Mediace

    APP
    Typo3
    7.6.2 – 7.6.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2011-3583CRITICAL9.8PL ✓same vendor

SQL Injection w TYPO3 Core przez niepoprawne prepared statements

CVE-2011-4628CRITICAL9.8PL ✓same vendor

TYPO3: Ominięcie mechanizmu uwierzytelniania w panelu administracyjnym

CVE-2019-11831CRITICAL9.8PL ✓same vendor

Path Traversal w PharStreamWrapper pozwala ominąć ochronę przed deserializacją

CVE-2019-11830CRITICAL9.8PL ✓same vendor

Obejście ochrony przed deserializacją w PharStreamWrapper dla TYPO3

CVE-2026-6553HIGH7.3same vendor

Changing backend users' passwords via the user settings module results in storing the cleartext password in th...