CVE-2017-14251: Malicious File Upload
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14251?
CVE-2017-14251 has a high severity due to its potential for remote authenticated users to execute arbitrary PHP code.
How do I fix CVE-2017-14251?
To fix CVE-2017-14251, upgrade TYPO3 to version 8.7.5 or 7.6.22 or later.
What versions of TYPO3 are affected by CVE-2017-14251?
CVE-2017-14251 affects TYPO3 versions 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4.
Who can exploit CVE-2017-14251?
CVE-2017-14251 can be exploited by remote authenticated users who have access to upload files.
What is the impact of exploiting CVE-2017-14251?
Exploiting CVE-2017-14251 allows an attacker to upload malicious files leading to arbitrary code execution on the server.