Record summary

CVE-2017-6370 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC.

Description

TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory7.6.15affected

Proofs of concept

1

Repository PoCs

GitHubfaizzaidi/TYPO3-v7.6.15-Unencrypted-Login-RequestRepository PoCby faizzaidiStars: 2Not analyzed2 files

151.4 KiB

GitHub

PoC details

References

4