CVE-2012-3527

Typo3 < 4.5.19 - Insecure Deserialization

Title source: rule

Description

view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."

Scores

EPSS 0.0207
EPSS Percentile 83.7%

Classification

CWE
CWE-502
Status draft

Affected Products (4)

typo3/typo3 < 4.5.19
debian/debian_linux
debian/debian_linux
typo3/cms < 4.5.19Packagist

Timeline

Published Sep 05, 2012
Tracked Since Feb 18, 2026