VulnerabilityModified
CVE-2011-4904
TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.
MEDIUM 6.5EPSS 1.14%
Does this matter?
Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.
Description
TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- typo3/typo3
- Source
- secalert@redhat.com
References
- https://security-tracker.debian.org/tracker/CVE-2011-4904Third Party Advisory
- https://typo3.org/security/advisory/typo3-core-sa-2011-001/#Missing_Access_ControlVendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-4904Third Party Advisory
- https://typo3.org/security/advisory/typo3-core-sa-2011-001/#Missing_Access_ControlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.