The query caching functionality in the Extbase Framework component in TYPO3 6.2.0 before 6.2.3 does not properly validate group permissions, which allows remote authenticated users to read arbitrary queries via unspecified vectors.
2014-06-03T14:55:11.287
2025-04-12T10:46:40.837
Deferred
CVSSv2: 4.0 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | typo3 | typo3 | 6.2 | Yes |
Application | typo3 | typo3 | 6.2.0 | Yes |
Application | typo3 | typo3 | 6.2.0 | Yes |
Application | typo3 | typo3 | 6.2.0 | Yes |
Application | typo3 | typo3 | 6.2.1 | Yes |
Application | typo3 | typo3 | 6.2.2 | Yes |