CVE-2012-3527
Typo3 < 4.5.19 - Insecure Deserialization
Title source: ruleDescription
view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."
References (6)
Scores
EPSS
0.0207
EPSS Percentile
83.7%
Classification
CWE
CWE-502
Status
draft
Affected Products (4)
typo3/typo3
< 4.5.19
debian/debian_linux
debian/debian_linux
typo3/cms
< 4.5.19Packagist
Timeline
Published
Sep 05, 2012
Tracked Since
Feb 18, 2026