Security Advisory

CVE-2024-22188

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-03-05 00:00:00
Last updated 2024-10-07 14:25:08
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.