CVE-2024-55893

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 749
CWE ID 352

Summary

CVE-2024-55893 is a vulnerability affecting the TYPO3 Content Management Framework's backend user interface. The issue involves a Cross-Site Request Forgery (CSRF) weakness in deep links and incorrect handling of state-changing actions in the Log Module. Successful exploitation requires the victim to have an active session on the backend and be tricked into clicking a malicious URL. The vulnerability can be triggered if the `security.backend.enforceReferrer` feature is disabled and `BE/cookieSameSite` configuration is set to lax or none. The Log Module flaw allows attackers to delete log entries. TYPO3 users are urged to update to versions 11.5.42 ELTS, 12.4.25 LTS, and 13.4.3 LTS to address the issue. No known workarounds exist.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share