CVE-2013-4320

TYPO3 6.0.0-6.0.8 and 6.1.0-6.1.3 - Authenticated Arbitrary File Read and Write via File Abstraction Layer

Title source: llm
STIX 2.1

Description

The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenticated users to create or read arbitrary files via a crafted URL.

References (1)

Core 1

Scores

EPSS 0.0013
EPSS Percentile 31.9%

Details

CWE
CWE-264
Status published
Products (14)
typo3/cms-core 6.0 - 6.0.9Packagist
typo3/typo3 6.1
typo3/typo3 6.1.1
typo3/typo3 6.1.2
typo3/typo3 6.1.3
typo3/typo3 6.0
typo3/typo3 6.0.1
typo3/typo3 6.0.2
typo3/typo3 6.0.3
typo3/typo3 6.0.4
... and 4 more
Published May 20, 2014
Tracked Since Feb 18, 2026