CVE-2011-4904

MEDIUM

TYPO3 < 4.4.9 and 4.5.x < 4.5.4 - Unauthenticated Information Disclosure via ExtDirect Endpoint

Title source: llm
STIX 2.1

Description

TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://security-tracker.debian.org/tracker/CVE-2011-4904

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 46.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-20
Status published
Products (2)
typo3/cms 0 - 4.4.9Packagist
typo3/typo3 4.4.0 - 4.4.9
Published Nov 06, 2019
Tracked Since Feb 18, 2026