CVE-2012-6146

TYPO3 4.5.0-4.5.20, 4.6.0-4.6.13, 4.7.0-4.7.5 - Authenticated Arbitrary Record History Access

Title source: llm
STIX 2.1

Description

The Backend History Module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 does not properly restrict access, which allows remote authenticated editors to read the history of arbitrary records via a crafted URL.

References (1)

Core 1

Scores

EPSS 0.0018
EPSS Percentile 38.7%

Details

CWE
CWE-264
Status published
Products (44)
typo3/cms 4.5 - 4.5.21Packagist
typo3/typo3 4.6.0
typo3/typo3 4.6.1
typo3/typo3 4.6.2
typo3/typo3 4.6.3
typo3/typo3 4.6.4
typo3/typo3 4.6.5
typo3/typo3 4.6.6
typo3/typo3 4.6.7
typo3/typo3 4.6.8
... and 34 more
Published May 20, 2014
Tracked Since Feb 18, 2026