CVE-2014-3942: Code Injection
The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authenticated editors to execute arbitrary PHP code via a serialized PHP object.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3942?
CVE-2014-3942 is classified as a medium severity vulnerability that allows remote authenticated editors to execute arbitrary PHP code.
How do I fix CVE-2014-3942?
To fix CVE-2014-3942, you need to upgrade TYPO3 to version 4.5.34, 4.7.19, 6.0.14, or 6.1.9 or later.
Which versions of TYPO3 are affected by CVE-2014-3942?
CVE-2014-3942 affects TYPO3 versions 4.5.0 to 4.5.33, 4.7.0 to 4.7.18, 6.0.0 to 6.0.13, and 6.1.0 to 6.1.8.
Can CVE-2014-3942 be exploited without authentication?
No, CVE-2014-3942 requires remote authenticated access to be exploited.
What kind of attack does CVE-2014-3942 enable?
CVE-2014-3942 enables remote authenticated attackers to execute arbitrary PHP code, potentially compromising the integrity of the website.