
Cloud Vulnerability DB
A community-led vulnerabilities database
A broken access control vulnerability was discovered in TYPO3 CMS's Import/Export module affecting versions 9.3.0 to 9.5.7. The vulnerability was disclosed on June 25, 2019, and assigned the identifier GHSA-g776-759r-pf6x. The issue allowed regular backend users to access import functionality that should only be available to admin users or users with specific TSconfig settings (TYPO3 Advisory).
The vulnerability allowed unauthorized access to import functionality in the Import/Export module, bypassing normal access controls. While database content imports were properly restricted by user permissions, the vulnerability enabled file uploads that could bypass File Abstraction Layer (FAL) restrictions. The vulnerability received a CVSS v3.1 base score of 4.3 (Moderate severity) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N (GitHub Advisory).
The primary impact of this vulnerability was the ability to upload *.form.yaml files, which could potentially be used to trigger a previous vulnerability (TYPO3-CORE-SA-2018-003) related to privilege escalation and SQL injection. This scenario required the Form Framework (ext:form) to be available on the affected website. The vulnerability only affected file uploads, while database content imports remained properly secured (TYPO3 Advisory).
Exploitation of this vulnerability requires a valid backend user account. The vulnerability specifically affects systems where the Form Framework is available. Executable files were not affected due to proper security measures through fileDenyPattern (GitHub Advisory).
The vulnerability was patched in TYPO3 version 9.5.8. Users are advised to update to this version or later to resolve the security issue. The fix was implemented by TYPO3 core team member Andreas Fernandez (TYPO3 Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."