Vulnerability DatabaseGHSA-cc97-g92w-jm65

GHSA-cc97-g92w-jm65
PHP vulnerability analysis and mitigation

Overview

A critical vulnerability (GHSA-cc97-g92w-jm65) was discovered in TYPO3 CMS, identified as Insecure Deserialization & Arbitrary Code Execution. The vulnerability affects versions 8.0.0 to 8.7.16, 9.0.0 to 9.3.1, and 7.0.0 to 7.6.29. It was disclosed on July 12, 2018, and has been assigned a CVSS v3.1 score of 9.8 (Critical) (GitHub Advisory).

Technical details

The vulnerability involves PHP's Phar file format, which can act as self-extracting archives leading to code execution when invoked. Phar files are not restricted to specific file extensions, allowing them to be disguised as image or text files (e.g., 'bundle.txt' instead of 'bundle.phar'). Due to insufficient user input sanitization, these Phar files could be triggered through manipulated URLs in TYPO3 backend forms (TYPO3 Advisory).

Impact

The vulnerability allows for arbitrary code execution through insecure deserialization. When successfully exploited, it provides an attacker with high levels of access to system confidentiality, integrity, and availability. The attack can be executed remotely with low complexity, though it requires valid backend user credentials (GitHub Advisory).

Exploitability

Exploitation requires a valid backend user account to manipulate URLs in TYPO3 backend forms. While theoretically possible in the TYPO3 frontend, no functional exploit has been identified for frontend attacks. The vulnerability can be exploited by uploading disguised Phar files that bypass standard file extension restrictions (TYPO3 Advisory).

Mitigation and workarounds

The vulnerability was patched in versions 7.6.30, 8.7.17, and 9.3.2. The fix implements a custom PHP stream wrapper that limits Phar file execution to those located in TYPO3 extensions (path typo3conf/ext/). Additionally, direct attack vectors were blocked, and Phar files stored in other locations cannot be invoked. Organizations are advised to ensure third-party extensions do not store arbitrary user-submitted files in typo3conf/ext/ directories (TYPO3 Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44741HIGH8.8
  • PHP logoPHP
  • pimcore/admin-ui-classic-bundle
NoYesAug 12, 2026
CVE-2026-47233MEDIUM6.5
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-47132MEDIUM5.4
  • PHP logoPHP
  • thorsten/phpmyfaq
NoYesAug 12, 2026
CVE-2026-47234MEDIUM4.4
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-49262LOW3
  • PHP logoPHP
  • aimeos/pagible
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management