
Cloud Vulnerability DB
A community-led vulnerabilities database
The XML External Entity (XXE) Processing vulnerability in TYPO3 Core (GHSA-qffc-gwpp-m2xr) was discovered and disclosed on February 23, 2016. This vulnerability affected TYPO3 CMS versions 6.2.0 to 6.2.18 and 7.6.0 to 7.6.3. The security issue was identified in the XML processing components of the TYPO3 Content Management System (TYPO3 Advisory, GitHub Advisory).
The vulnerability allows for XML External Entity (XXE) processing within all XML processing components of the TYPO3 CMS. The severity was rated as High, with a suggested CVSS v2.0 score of AV:N/AC:M/Au:N/C:P/I:P/A:P/E:P/RL:O/RC:C. Systems using PHP with libxml2 version 2.9 or higher were protected by default, as this library version disallows external entity processing by default (TYPO3 Advisory).
The vulnerability could lead to the loading of internal and/or external file content within an XML structure. Additionally, it enabled potential attackers to inject arbitrary files for XML Denial of Service attacks, compromising system security and stability (TYPO3 Advisory, GitHub Advisory).
The vulnerability required network access and moderate complexity to exploit, with no authentication required as indicated by the CVSS metrics. The exploit proof was confirmed, as reflected in the CVSS scoring component RC:C (TYPO3 Advisory).
The vulnerability was patched in TYPO3 versions 6.2.19 and 7.6.4. Users were advised to update to these versions to address the security issue. Additionally, systems using PHP with libxml2 version 2.9 or higher had built-in protection against this vulnerability due to the library's default security settings (TYPO3 Advisory, GitHub Advisory).
The security team member Marcus Krause was credited with discovering and reporting the issue. The TYPO3 team recommended users to follow the TYPO3 Security Guide and subscribe to the typo3-announce mailing list for future security updates (TYPO3 Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."