CVE-2014-8874: Infoleak
Published Dec 2, 2014
·Updated
The kequestionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, which makes it easier for remote attackers to obtain sensitive information via a direct request.
Affected Software
1 affected component
Kennziffer Ke Questionnaire Typo3<=2.5.2
Event History
Dec 2, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8874?
CVE-2014-8874 is considered to have a medium severity level due to its potential for unauthorized access to sensitive information.
2
How do I fix CVE-2014-8874?
To fix CVE-2014-8874, update the ke_questionnaire extension to version 2.5.3 or later.
3
What causes CVE-2014-8874?
CVE-2014-8874 is caused by the usage of predictable names for questionnaire answer forms in the ke_questionnaire extension.
4
What are the potential impacts of CVE-2014-8874?
The potential impacts of CVE-2014-8874 include unauthorized access to sensitive questionnaire data via direct requests.
5
Which versions of the ke_questionnaire extension are affected by CVE-2014-8874?
CVE-2014-8874 affects ke_questionnaire versions 2.5.2 and earlier.