EIP-2026-112832

PRE-CVE

TYPO3 11.5.24 - Path Traversal (Authenticated)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112832. PoCs published by Saeed reza Zamanian.

AI-analyzed exploit summary This is a technical writeup describing a path traversal vulnerability in TYPO3 11.5.24, where an authenticated attacker can read arbitrary files by manipulating the basePath parameter in a POST request. The steps to exploit the vulnerability are clearly outlined, including the specific HTTP request format.

Description

TYPO3 11.5.24 - Path Traversal (Authenticated)

Exploits (1)

exploitdb WRITEUP
by Saeed reza Zamanian · textwebappsphp
https://www.exploit-db.com/exploits/51901

This is a technical writeup describing a path traversal vulnerability in TYPO3 11.5.24, where an authenticated attacker can read arbitrary files by manipulating the basePath parameter in a POST request. The steps to exploit the vulnerability are clearly outlined, including the specific HTTP request format.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: TYPO3 11.5.24
Auth required
Prerequisites: Authenticated access to the TYPO3 administrator panel
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026