Wiz Agents & Workflows are here
Vulnerability DatabaseGHSA-x428-565f-8xj2

GHSA-x428-565f-8xj2
PHP vulnerability analysis and mitigation

Overview

A security vulnerability was discovered in TYPO3 CMS affecting versions 8.0.0-8.7.26 and 9.0.0-9.5.7, identified as TYPO3-CORE-SA-2019-019. The vulnerability was related to the Backend API configuration using Page TSconfig, which could be exploited for arbitrary code execution and cross-site scripting. The issue was disclosed on June 25th, 2019, affecting the TYPO3 CMS core component, specifically the Backend API (ext:backend) subcomponent (TYPO3 Advisory).

Technical details

The vulnerability stemmed from TSconfig fields in page properties within backend forms that could be used to inject malicious sequences. Additionally, the tsconfig_includes field was vulnerable to directory traversal, which could lead to unauthorized access to TSconfig settings. The vulnerability received a CVSS v3.1 base score of 8.8 (High severity) with the following vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (GitHub Advisory).

Impact

The vulnerability could allow attackers with valid backend user credentials to execute arbitrary code and perform cross-site scripting attacks through the manipulation of pages.TSconfig and pages.tsconfig_includes fields. This could potentially lead to unauthorized access to sensitive data, system compromise, and website defacement (TYPO3 Advisory).

Mitigation and workarounds

The vulnerability was patched in TYPO3 versions 8.7.27 and 9.5.8. The fix includes denying non-admin users from modifying the pages.TSconfig and pages.tsconfig_includes fields. Users are strongly advised to upgrade to these patched versions to protect their systems (TYPO3 Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-wprj-9cvc-5w37HIGH7.5
  • PHPPHP
  • wwbn/avideo
NoNoMar 29, 2026
CVE-2026-34036MEDIUM6.5
  • PHPPHP
  • dolibarr/dolibarr
NoNoMar 31, 2026
CVE-2026-33887MEDIUM5.4
  • PHPPHP
  • statamic/cms
NoYesMar 27, 2026
CVE-2026-27599MEDIUM4.7
  • PHPPHP
  • ci4-cms-erp/ci4ms
NoYesMar 30, 2026
CVE-2026-34372MEDIUMN/A
  • PHPPHP
  • sulu/sulu
NoYesMar 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management