CVE-2013-4321

TYPO3 6.0.0-6.0.8 and 6.1.0-6.1.3 - Authenticated Remote Code Execution via File Extension in FAL Renaming

Title source: llm
STIX 2.1

Description

The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors to execute arbitrary PHP code via unspecified characters in the file extension when renaming a file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4250.

References (1)

Core 1

Scores

EPSS 0.0049
EPSS Percentile 65.6%

Details

CWE
CWE-94
Status published
Products (13)
typo3/cms 6.0.0 - 6.0.9Packagist
typo3/typo3 6.1
typo3/typo3 6.1.1
typo3/typo3 6.1.2
typo3/typo3 6.1.3
typo3/typo3 6.0
typo3/typo3 6.0.1
typo3/typo3 6.0.2
typo3/typo3 6.0.3
typo3/typo3 6.0.4
... and 3 more
Published May 20, 2014
Tracked Since Feb 18, 2026