GHSA-4r76-xr68-w7m7: TYPO3 may allow editors to change, create, or delete metadata of files not within their file mounts
8.8
CVSS Score
3.1
Basic Information
CVE ID
-
GHSA ID
EPSS Score
-
CWE
Published
5/30/2024
Updated
5/30/2024
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| typo3/cms | composer | >= 6.2.0, < 6.2.14 | 6.2.14 |
| typo3/cms | composer | >= 7.0.0, < 7.3.1 | 7.3.1 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stemmed from missing access checks in inline record handling. The patch added hooks in checkAccess methods (via SC_OPTIONS) to call FileMetadataPermissionsAspect for permission validation. Vulnerable versions lacked these hooks, allowing editors to manipulate metadata without proper file mount validation. The functions are explicitly modified in the security commit diff, confirming their role in the access control flaw.