Arbitrary Code Execution in TYPO3 CMS
Critical severity
GitHub Reviewed
Published
Jun 5, 2024
to the GitHub Advisory Database
•
Updated Jun 5, 2024
Package
Affected versions
>= 7.6.0, < 7.6.22
>= 8.0.0, < 8.7.5
Patched versions
7.6.22
8.7.5
Description
Published to the GitHub Advisory Database
Jun 5, 2024
Reviewed
Jun 5, 2024
Last updated
Jun 5, 2024
Due to a missing file extension in the fileDenyPattern, backend user are allowed to upload *.pht files which can be executed in certain web server setups. The new default fileDenyPattern is the following, which might have been overridden in the TYPO3 Install Tool.
References