CVE-2013-7075: Medium severity Typo3 TYPO3 vulnerability
The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated backend users to unserialize arbitrary PHP objects, delete arbitrary files, and possibly have other unspecified impacts via an unspecified parameter, related to a "missing signature."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 6.1.7 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 6.0.12 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.7.17 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.5.32
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7075?
CVE-2013-7075 is classified as a critical vulnerability due to the potential for remote authenticated users to exploit it and perform unauthorized actions.
How do I fix CVE-2013-7075?
To remediate CVE-2013-7075, upgrade TYPO3 to version 6.1.7 or later, 6.0.12 or later, or 4.7.17 or later.
What versions of TYPO3 are affected by CVE-2013-7075?
CVE-2013-7075 affects TYPO3 versions 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6.
What risks are associated with CVE-2013-7075?
Exploitation of CVE-2013-7075 can lead to the ability to unserialize arbitrary PHP objects, delete files, and potentially cause further unspecified impacts.
Who can be exploited by CVE-2013-7075?
CVE-2013-7075 can be exploited by remote authenticated backend users, emphasizing the need for secure user management practices.