VulnerabilityModified
CVE-2020-25025
The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows Information Disclosure (translatable fields).
MEDIUM 4.3EPSS 0.82%
Does this matter?
Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.
Description
The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows Information Disclosure (translatable fields).
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- localization manager project/localization manager
- Source
- cve@mitre.org
References
- https://typo3.org/help/security-advisoriesVendor Advisory
- https://typo3.org/security/advisory/typo3-ext-sa-2020-016Patch, Vendor Advisory
- https://typo3.org/help/security-advisoriesVendor Advisory
- https://typo3.org/security/advisory/typo3-ext-sa-2020-016Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.