Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2092 | TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, and 12.4.4, in multi-site scenarios, enumerating the HTTP query parameters `id` and `L` allowed out-of-scope access to rendered content in the website frontend. For instance, this allowed visitors to access content of an internal site by adding handcrafted query parameters to the URL of a site that was publicly available. TYPO3 versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, 12.4.4 fix the problem. |
Github GHSA |
GHSA-jq6g-4v5m-wm9r | Information Disclosure due to Out-of-scope Site Resolution |
Tue, 15 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-15T18:40:37.114Z
Reserved: 2023-07-18T16:28:12.076Z
Link: CVE-2023-38499
Updated: 2024-08-02T17:46:55.097Z
Status : Modified
Published: 2023-07-25T21:15:10.997
Modified: 2024-11-21T08:13:42.133
Link: CVE-2023-38499
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA