VulnerabilityModified
CVE-2017-6370
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
MEDIUM 5.3EPSS 0.99%
Does this matter?
Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.
Description
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.99% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- typo3/typo3
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/97071
- https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-RequestExploit, Third Party Advisory
- http://www.securityfocus.com/bid/97071
- https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-RequestExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.