CVE-2022-23503: TYPO3 vulnerable to Arbitrary Code Execution via Form Framework
TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Code Injection. Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend module, it is possible to inject code instructions to be processed and executed via TypoScript as PHP code. The existence of individual TypoScript instructions for a particular form item and a valid backend user account with access to the form module are needed to exploit this vulnerability. This issue is patched in versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1.
Other sources
TYPO3-CORE-SA-2022-015: Arbitrary Code Execution via Form Framework
Affected Software
Event History
Frequently Asked Questions
What is TYPO3-CORE-SA-2022-015?
TYPO3-CORE-SA-2022-015 is a vulnerability within TYPO3 CMS that allows for arbitrary code execution via the Form Framework.
Which versions of TYPO3 are affected by TYPO3-CORE-SA-2022-015?
Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to TYPO3-CORE-SA-2022-015.
How severe is TYPO3-CORE-SA-2022-015?
TYPO3-CORE-SA-2022-015 has a severity score of 8.8, which is considered high.
How can I fix TYPO3-CORE-SA-2022-015?
To fix TYPO3-CORE-SA-2022-015, you should update TYPO3 CMS to version 8.7.49, 9.5.38, 10.4.33, 11.5.20, or 12.1.1.
Where can I find more information about TYPO3-CORE-SA-2022-015?
More information about TYPO3-CORE-SA-2022-015 can be found in the TYPO3 security advisory TYPO3-CORE-SA-2022-015 and the GitHub security advisories GHSA-c5wx-6c2c-f7rm.