CVE-2010-3716: Input Validation
Published Oct 25, 2010
·Updated
The beusercreation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST request that creates a user account with arbitrary group memberships.
Affected Software
22 affected components
Typo3 TYPO3=4.2.10
Typo3 TYPO3=4.3.6
Typo3 TYPO3=4.2.14
Typo3 TYPO3=4.3.5
Typo3 TYPO3=4.2.4
Typo3 TYPO3=4.2.5
Typo3 TYPO3=4.2.11
Typo3 TYPO3=4.2.0
Typo3 TYPO3=4.2.8
Typo3 TYPO3=4.2.13
Typo3 TYPO3=4.2.3
Typo3 TYPO3=4.2.1
Typo3 TYPO3=4.3.2
Typo3 TYPO3=4.2.12
Typo3 TYPO3=4.2.6
Typo3 TYPO3=4.3.0
Typo3 TYPO3=4.2.2
Typo3 TYPO3=4.3.3
Typo3 TYPO3=4.3.4
Typo3 TYPO3=4.3.1
Typo3 TYPO3=4.2.7
Typo3 TYPO3=4.2.9
Event History
Oct 25, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3716?
CVE-2010-3716 is classified as a medium severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2010-3716?
To fix CVE-2010-3716, upgrade TYPO3 to version 4.2.15 or 4.3.7 or later.
3
What systems are affected by CVE-2010-3716?
CVE-2010-3716 affects TYPO3 versions 4.2.x before 4.2.15 and 4.3.x before 4.3.7.
4
What type of vulnerability is CVE-2010-3716?
CVE-2010-3716 is a vulnerability that allows remote authenticated users to gain elevated privileges.
5
Can CVE-2010-3716 be exploited remotely?
Yes, CVE-2010-3716 can be exploited remotely by authenticated users through a crafted POST request.