CVE-2022-23503
HIGHTYPO3 < 8.7.49, 9.5.38, 10.4.33, 11.5.20, 12.1.1 - Authenticated Code Injection via Form Designer TypoScript
Title source: llmDescription
TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Code Injection. Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend module, it is possible to inject code instructions to be processed and executed via TypoScript as PHP code. The existence of individual TypoScript instructions for a particular form item and a valid backend user account with access to the form module are needed to exploit this vulnerability. This issue is patched in versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_confirm
https://github.com/TYPO3/typo3/security/advisories/GHSA-c5wx-6c2c-f7rm
Scores
CVSS v3
7.5
EPSS
0.0052
EPSS Percentile
66.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (3)
typo3/cms
10.0.0 - 10.4.33Packagist
typo3/cms-core
8.0.0 - 8.7.49Packagist
typo3/typo3
8.0.0 - 8.7.49
Published
Dec 14, 2022
Tracked Since
Feb 18, 2026