CVE-2009-3628

Typo3 < 4.0.12 - Information Disclosure

Title source: rule

Description

The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to determine an encryption key via crafted input to a tt_content form element.

Scores

EPSS 0.0023
EPSS Percentile 45.2%

Classification

CWE
CWE-200
Status draft

Affected Products (50)

typo3/typo3 < 4.0.12
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
... and 35 more

Timeline

Published Nov 02, 2009
Tracked Since Feb 18, 2026