Release date:
Updated on: 2014-06-04
Affected Systems:
TYPO3 TYPO3 6.x
TYPO3 TYPO3 4.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-3942
Typo3 is an open-source Content Management System (CMS) and Content Management Framework (CMF ).
The Color Picker Wizard component in versions earlier than TYPO3 4.5.34, 4.7.19, 6.0.14, 6.1.9, and 6.2.3 has a security vulnerability. The authenticated remote editor can serialize PHP objects, attackers can exploit this vulnerability to execute arbitrary PHP code.
<* Source: Helmut Hummel
Link: http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TYPO3
-----
TYPO3 has released a Security Bulletin (typo3-core-sa-2014-001) and corresponding patches for this:
Typo3-core-sa-2014-001: TYPO3-CORE-SA-2014-001: Multiple Vulnerabilities in TYPO3 CMS
Link: http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/
For more information about Typo3, click here.
Typo3: click here
This article permanently updates the link address: