-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from missing access checks in inline record handling. The patch added hooks in checkAccess methods (via SC_OPTIONS) to call FileMetadataPermissionsAspect for permission validation. Vulnerable versions lacked these hooks, allowing editors to manipulate metadata without proper file mount validation. The functions are explicitly modified in the security commit diff, confirming their role in the access control flaw.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| typo3/cms | composer | >= 6.2.0, < 6.2.14 | 6.2.14 |
| typo3/cms | composer | >= 7.0.0, < 7.3.1 | 7.3.1 |
Ongoing coverage of React2Shell