Skip to content

Arbitrary Code Execution via Form Framework

High
ohader published GHSA-c5wx-6c2c-f7rm Dec 13, 2022

Package

composer typo3/cms-core (Composer)

Affected versions

8.0.0-8.7.48, 9.0.0-9.5.37, 10.0.0-10.4.32, 11.0.0-11.5.19, 12.0.0-12.1.0

Patched versions

8.7.49, 9.5.38, 10.4.33, 11.5.20, 12.1.1

Description

CVSS: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C (7.0)

Problem

Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend module, it was possible to inject code instructions to be processed and executed via TypoScript as PHP code.

The existence of individual TypoScript instructions for a particular form item (known as formDefinitionOverrides) and a valid backend user account with access to the form module are needed to exploit this vulnerability.

Solution

Update to TYPO3 versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1 that fix the problem described above.

Credits

Thanks to Sabine Deeken who reported this issue and to TYPO3 core team member Ralf Zimmermann who fixed the issue.

References

Severity

High
7.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE ID

CVE-2022-23503

Weaknesses