CVE-2009-3628: Infoleak
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to determine an encryption key via crafted input to a ttcontent form element.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3628?
CVE-2009-3628 has a severity rating of medium due to its ability to allow remote authenticated users to leak sensitive encryption keys.
How do I fix CVE-2009-3628?
To fix CVE-2009-3628, you should update TYPO3 to version 4.3beta2 or later, 4.2.10, or 4.1.13.
Which versions of TYPO3 are affected by CVE-2009-3628?
CVE-2009-3628 affects TYPO3 versions up to 4.0.13, all 4.1.x versions before 4.1.13, all 4.2.x versions before 4.2.10, and all 4.3.x versions before 4.3beta2.
What type of user can exploit CVE-2009-3628?
CVE-2009-3628 can be exploited by remote authenticated users who can submit crafted input to a tt_content form element.
What component of TYPO3 is vulnerable in CVE-2009-3628?
The Backend subcomponent of TYPO3 is the vulnerable component in CVE-2009-3628.