Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22188


TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.


Published

2024-03-05T02:15:27.443

Last Modified

2025-09-15T17:21:54.450

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application typo3 typo3 < 8.7.57 Yes
Application typo3 typo3 < 9.5.46 Yes
Application typo3 typo3 < 10.4.43 Yes
Application typo3 typo3 < 11.5.35 Yes
Application typo3 typo3 < 12.4.11 Yes
Application typo3 typo3 13.0.0 Yes

References