CVE-2017-6370: Medium severity Typo3 TYPO3 vulnerability
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6370?
CVE-2017-6370 is considered a moderate severity vulnerability due to its potential to expose sensitive user information.
How do I fix CVE-2017-6370?
To fix CVE-2017-6370, you should upgrade TYPO3 to a version that does not send sensitive information in clear text, specifically any version after 7.6.15.
What kind of information is exposed in CVE-2017-6370?
CVE-2017-6370 can expose sensitive information such as userident and username fields through unencrypted HTTP requests.
What versions of TYPO3 are affected by CVE-2017-6370?
CVE-2017-6370 specifically affects TYPO3 version 7.6.15.
Can CVE-2017-6370 be exploited remotely?
Yes, CVE-2017-6370 can be exploited remotely by attackers sniffing network traffic to capture sensitive information.