Privilege Escalation in TYPO3 CMS
Moderate severity
GitHub Reviewed
Published
Jun 5, 2024
to the GitHub Advisory Database
Package
Affected versions
>= 6.2.0, < 6.2.20
>= 7.6.0, < 7.6.5
>= 8.0.0, < 8.0.1
Patched versions
6.2.20
7.6.5
8.0.1
Description
Published to the GitHub Advisory Database
Jun 5, 2024
Reviewed
Jun 5, 2024
The workspace/ version preview link created by a privileged (backend) user could be abused to obtain certain editing permission, if the admin panel is configured to be shown. A valid preview link is required to exploit this vulnerability.
References