CVE-2013-4321: Code Injection
The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors to execute arbitrary PHP code via unspecified characters in the file extension when renaming a file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4250.
Other sources
The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 allows remote authenticated editors to execute arbitrary PHP code via unspecified characters in the file extension when renaming a file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4250.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4321?
CVE-2013-4321 is considered a high severity vulnerability due to its ability to allow remote authenticated users to execute arbitrary PHP code.
How do I fix CVE-2013-4321?
To fix CVE-2013-4321, you should upgrade TYPO3 to version 6.0.8 or 6.1.4 or later.
Which versions of TYPO3 are affected by CVE-2013-4321?
CVE-2013-4321 affects TYPO3 versions 6.0.x prior to 6.0.8 and 6.1.x prior to 6.1.4.
What type of users are impacted by CVE-2013-4321?
CVE-2013-4321 impacts remote authenticated editors who are able to rename files.
What is the main issue caused by CVE-2013-4321?
The main issue caused by CVE-2013-4321 is the execution of arbitrary PHP code through the file renaming process.