CVE-2016-5091: High severity Typo3 TYPO3 vulnerability
Published Jan 23, 2017
·Updated
Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action.
Affected Software
22 affected componentsFixes available
composer/typo3/cms-extbase=8.1.1
composer/typo3/cms-extbase>=7.0<7.6.8
7.6.8
composer/typo3/cms-extbase<6.2.24
6.2.24
Typo3 TYPO3<=6.2.23
Typo3 TYPO3=7.0.0
Typo3 TYPO3=7.0.2
Typo3 TYPO3=7.1.0
Typo3 TYPO3=7.2.0
Typo3 TYPO3=7.3.0
Typo3 TYPO3=7.3.1
Typo3 TYPO3=7.4.0
Typo3 TYPO3=7.5.0
Typo3 TYPO3=7.6.0
Typo3 TYPO3=7.6.1
Typo3 TYPO3=7.6.2
Typo3 TYPO3=7.6.3
Typo3 TYPO3=7.6.4
Typo3 TYPO3=7.6.5
Typo3 TYPO3=7.6.6
Typo3 TYPO3=7.6.7
Typo3 TYPO3=7.6.8
Typo3 TYPO3=8.1.1
Remediation
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 17, 2022
Advisory Published
03:02 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-5091?
CVE-2016-5091 has a severity rating of Moderate, due to the potential for sensitive information disclosure and remote code execution.
2
How do I fix CVE-2016-5091?
To fix CVE-2016-5091, upgrade TYPO3 Extbase to version 6.2.24 or higher, 7.6.8 or higher, or 8.1.1.
3
Which TYPO3 versions are affected by CVE-2016-5091?
CVE-2016-5091 affects TYPO3 versions prior to 6.2.24, 7.x before 7.6.8, and 8.1.1.
4
What potential impacts does CVE-2016-5091 have on my system?
CVE-2016-5091 could allow remote attackers to obtain sensitive information or potentially execute arbitrary code.
5
Is there a workaround for CVE-2016-5091?
There are no known effective workarounds for CVE-2016-5091; upgrading to a patched version is recommended.