CVE-2024-34537

medium

Description

TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1.

References

https://www.mgm-sp.com/cve/denial-of-service-in-typo3-bookmark-toolbar

https://typo3.org/security/advisory/typo3-core-sa-2024-011

https://github.com/TYPO3/typo3/security/advisories/GHSA-ffcv-v6pw-qhrp

Details

Source: Mitre, NVD

Published: 2024-10-28

Updated: 2024-10-31

Risk Information

CVSS v2

Base Score: 3.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 4.9

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Severity: Medium