CVE-2019-11832

HIGH

TYPO3 8.0.0-8.7.24 and 9.0.0-9.5.5 - Remote Code Execution via Image Processing Configuration

Title source: llm
STIX 2.1

Description

TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108305

Scores

CVSS v3 7.5
EPSS 0.0090
EPSS Percentile 75.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (3)
typo3/cms 8.0.0 - 8.7.25Packagist
typo3/cms-core 8.0.0 - 8.7.25Packagist
typo3/typo3 8.0.0 - 8.7.25
Published May 09, 2019
Tracked Since Feb 18, 2026