CVE-2017-6370: Medium severity Typo3 TYPO3 vulnerability

Published Mar 17, 2017
·
Updated

TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.

Affected Software

2 affected components
composer/typo3/cms=7.6.15
Typo3 TYPO3=7.6.15

Event History

Mar 17, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
May 13, 2022
Advisory Published
via GitHub·01:46 AM

Frequently Asked Questions

1

What is the severity of CVE-2017-6370?

CVE-2017-6370 is considered a moderate severity vulnerability due to its potential to expose sensitive user information.

2

How do I fix CVE-2017-6370?

To fix CVE-2017-6370, you should upgrade TYPO3 to a version that does not send sensitive information in clear text, specifically any version after 7.6.15.

3

What kind of information is exposed in CVE-2017-6370?

CVE-2017-6370 can expose sensitive information such as userident and username fields through unencrypted HTTP requests.

4

What versions of TYPO3 are affected by CVE-2017-6370?

CVE-2017-6370 specifically affects TYPO3 version 7.6.15.

5

Can CVE-2017-6370 be exploited remotely?

Yes, CVE-2017-6370 can be exploited remotely by attackers sniffing network traffic to capture sensitive information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203