CVE-2014-3946

TYPO3 6.2.0-6.2.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

The query caching functionality in the Extbase Framework component in TYPO3 6.2.0 before 6.2.3 does not properly validate group permissions, which allows remote authenticated users to read arbitrary queries via unspecified vectors.

References (3)

Core 3
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2014/dsa-2942
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/06/03/2

Scores

EPSS 0.0015
EPSS Percentile 35.2%

Details

CWE
CWE-200
Status published
Products (5)
typo3/cms 6.2.0 - 6.2.3Packagist
typo3/typo3 6.2
typo3/typo3 6.2.0 beta1 (3 CPE variants)
typo3/typo3 6.2.1
typo3/typo3 6.2.2
Published Jun 03, 2014
Tracked Since Feb 18, 2026