TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, the export functionality fails to limit the result set to allowed columns of a particular database table. This way, authenticated users can export internal details of database tables they already have access to. TYPO3 versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, 11.5.11 fix the problem described above. In order to address this issue, access to mentioned export functionality is completely denied for regular backend users.
History

Wed, 23 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-06-14T20:40:22.000Z

Updated: 2025-04-23T18:15:44.206Z

Reserved: 2022-05-18T00:00:00.000Z

Link: CVE-2022-31046

cve-icon Vulnrichment

Updated: 2024-08-03T07:03:40.293Z

cve-icon NVD

Status : Modified

Published: 2022-06-14T21:15:15.987

Modified: 2024-11-21T07:03:46.810

Link: CVE-2022-31046

cve-icon Redhat

No data.