CVE-2013-7080: Medium severity Typo3 TYPO3 vulnerability
The creating record functionality in Extension table administration library (feuseradminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 6.0.11 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 4.7.16 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 4.5.31 - Upgrade
Upgrade
TYPO3 (Extension table administration library feuser_adminLib.inc)to a version that resolves this vulnerability.Fixed in 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11
Event History
Frequently Asked Questions
What are the affected versions of TYPO3 for CVE-2013-7080?
The affected versions for CVE-2013-7080 range from TYPO3 4.5.0 to 4.5.31, 4.7.0 to 4.7.16, and 6.0.0 to 6.0.11.
What is the severity of CVE-2013-7080?
CVE-2013-7080 is classified as a medium-severity vulnerability due to the potential for unauthorized data manipulation.
How do I fix CVE-2013-7080?
To fix CVE-2013-7080, update your TYPO3 installation to versions 4.5.31, 4.7.16, or 6.0.11 and later.
Can CVE-2013-7080 be exploited remotely?
Yes, CVE-2013-7080 can be exploited by remote attackers to manipulate database configurations.
What impact does CVE-2013-7080 have on TYPO3 installations?
CVE-2013-7080 allows attackers to write to arbitrary fields in the TYPO3 configuration database, potentially leading to data loss or compromise.