CVE-2009-3628

high

Description

The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to determine an encryption key via crafted input to a tt_content form element.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/53917

http://www.vupen.com/english/advisories/2009/3009

http://www.securityfocus.com/bid/36801

http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016

http://secunia.com/advisories/37122

http://marc.info/?l=oss-security&m=125632856206736&w=2

Details

Source: Mitre, NVD

Published: 2009-11-02

Updated: 2025-04-09

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.00227