CVE-2013-4250: Input Validation
Published May 20, 2014
·Updated
The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.
Affected Software
14 affected componentsFixes available
Typo3 TYPO3=6.0
Typo3 TYPO3=6.0.1
Typo3 TYPO3=6.0.2
Typo3 TYPO3=6.0.3
Typo3 TYPO3=6.0.4
Typo3 TYPO3=6.0.5
Typo3 TYPO3=6.0.6
Typo3 TYPO3=6.0.7
Typo3 TYPO3=6.0.9
Typo3 TYPO3=6.1
Typo3 TYPO3=6.1.1
Typo3 TYPO3=6.1.2
composer/typo3/cms>=6.1.0<6.1.3
6.1.3
composer/typo3/cms>=6.0.0<6.0.8
6.0.8
Event History
May 20, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
May 17, 2022
Advisory Published
via GitHub·04:43 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-4250?
CVE-2013-4250 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2013-4250?
To fix CVE-2013-4250, upgrade to TYPO3 versions 6.0.8 or 6.1.3 or later.
3
Which versions of TYPO3 are affected by CVE-2013-4250?
CVE-2013-4250 affects TYPO3 versions 6.0.x before 6.0.8 and 6.1.x before 6.1.3.
4
What type of vulnerability is CVE-2013-4250?
CVE-2013-4250 is a file upload vulnerability that allows execution of arbitrary PHP code.
5
Can unauthenticated users exploit CVE-2013-4250?
No, CVE-2013-4250 requires remote authenticated editors to exploit the vulnerability.