97071vdb entry
http://www.securityfocus.com/bid/97071 CVE-2017-6370
MEDIUM
TYPO3 Information Disclosure Vulnerability
Record summary
CVE-2017-6370 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC.
Description
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
typo3/cmsBrowse Packagist / typo3/cms | GitHub Advisory | 7.6.15 | affected |
Proofs of concept
1Repository PoCs
GitHubfaizzaidi/TYPO3-v7.6.15-Unencrypted-Login-RequestRepository PoCby faizzaidiStars: 2Not analyzed2 files
References
4github.com
https://github.com/TYPO3/typo3 github.com
https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-6370