TYPO3 Frontend vulnerable to Unauthenticated Path Disclosure
Moderate severity
GitHub Reviewed
Published
May 30, 2024
to the GitHub Advisory Database
•
Updated May 30, 2024
Package
Affected versions
>= 6.2.0, < 6.2.15
>= 7.0.0, < 7.4.0
Patched versions
6.2.15
7.4.0
Description
Published to the GitHub Advisory Database
May 30, 2024
Reviewed
May 30, 2024
Last updated
May 30, 2024
It has been discovered, that calling a PHP script which is delivered with TYPO3 for testing purposes, discloses the absolute server path to the TYPO3 installation.
References