CVE-2013-4250

TYPO3 6.0.0-6.0.7 and 6.1.0-6.1.2 - Authenticated Arbitrary PHP Code Execution via File Upload

Title source: llm
STIX 2.1

Description

The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.

References (1)

Core 1

Scores

EPSS 0.0039
EPSS Percentile 60.3%

Details

CWE
CWE-20
Status published
Products (13)
typo3/cms 6.0.0 - 6.0.8Packagist
typo3/typo3 6.0
typo3/typo3 6.0.1
typo3/typo3 6.0.2
typo3/typo3 6.0.3
typo3/typo3 6.0.4
typo3/typo3 6.0.5
typo3/typo3 6.0.6
typo3/typo3 6.0.7
typo3/typo3 6.0.9
... and 3 more
Published May 20, 2014
Tracked Since Feb 18, 2026