CVE Vulnerabilities

CVE-2012-6146

Published: May 20, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Backend History Module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 does not properly restrict access, which allows remote authenticated editors to read the history of arbitrary records via a crafted URL.

Affected Software

NameVendorStart VersionEnd Version
Typo3Typo34.6.0 (including)4.6.0 (including)
Typo3Typo34.6.1 (including)4.6.1 (including)
Typo3Typo34.6.2 (including)4.6.2 (including)
Typo3Typo34.6.3 (including)4.6.3 (including)
Typo3Typo34.6.4 (including)4.6.4 (including)
Typo3Typo34.6.5 (including)4.6.5 (including)
Typo3Typo34.6.6 (including)4.6.6 (including)
Typo3Typo34.6.7 (including)4.6.7 (including)
Typo3Typo34.6.8 (including)4.6.8 (including)
Typo3Typo34.6.9 (including)4.6.9 (including)
Typo3Typo34.6.10 (including)4.6.10 (including)
Typo3Typo34.6.11 (including)4.6.11 (including)
Typo3Typo34.6.12 (including)4.6.12 (including)
Typo3Typo34.6.13 (including)4.6.13 (including)

References