CVE-2011-4902: Input Validation
Published Nov 6, 2019
·Updated
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.
Affected Software
7 affected componentsFixes available
composer/typo3/cms>=4.5.0<4.5.4
4.5.4
composer/typo3/cms>=4.4.0<4.4.9
4.4.9
composer/typo3/cms<4.3.12
4.3.12
debian/typo3-src
Typo3 TYPO3>=4.5.0<4.5.4
Typo3 TYPO3>=4.3.0<4.3.12
Typo3 TYPO3>=4.4.0<4.4.9
Event History
Nov 6, 2019
CVE Published
via MITRE·04:53 PM
Data Sourced
via MITRE·04:53 PM
DescriptionWeakness
Apr 22, 2022
Advisory Published
via GitHub·12:24 AM
Frequently Asked Questions
1
What is the severity of CVE-2011-4902?
The severity of CVE-2011-4902 is medium.
2
How does CVE-2011-4902 impact TYPO3?
CVE-2011-4902 allows remote attackers to delete arbitrary files on the webserver.
3
What versions of TYPO3 are affected by CVE-2011-4902?
TYPO3 versions before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 are affected by CVE-2011-4902.
4
Where can I find more information about CVE-2011-4902?
You can find more information about CVE-2011-4902 at the TYPO3 security advisory (https://typo3.org/security/advisory/typo3-core-sa-2011-001/#Unserialize) and the Debian security tracker (https://security-tracker.debian.org/tracker/CVE-2011-4902).
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2011-4902?
The Common Weakness Enumeration (CWE) ID for CVE-2011-4902 is CWE-20.