CVE-2024-55893
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-55893 is a vulnerability affecting the TYPO3 Content Management Framework's backend user interface. The issue involves a Cross-Site Request Forgery (CSRF) weakness in deep links and incorrect handling of state-changing actions in the Log Module. Successful exploitation requires the victim to have an active session on the backend and be tricked into clicking a malicious URL. The vulnerability can be triggered if the `security.backend.enforceReferrer` feature is disabled and `BE/cookieSameSite` configuration is set to lax or none. The Log Module flaw allows attackers to delete log entries. TYPO3 users are urged to update to versions 11.5.42 ELTS, 12.4.25 LTS, and 13.4.3 LTS to address the issue. No known workarounds exist.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- TYPO3
Affected Vendors
- TYPO3