CVE Vulnerabilities

CVE-2016-5091

Published: Jan 23, 2017 | Modified: Apr 20, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action.

Affected Software

NameVendorStart VersionEnd Version
Typo3Typo3*6.2.23 (including)
Typo3Typo37.0.0 (including)7.0.0 (including)
Typo3Typo37.0.2 (including)7.0.2 (including)
Typo3Typo37.1.0 (including)7.1.0 (including)
Typo3Typo37.2.0 (including)7.2.0 (including)
Typo3Typo37.3.0 (including)7.3.0 (including)
Typo3Typo37.3.1 (including)7.3.1 (including)
Typo3Typo37.4.0 (including)7.4.0 (including)
Typo3Typo37.5.0 (including)7.5.0 (including)
Typo3Typo37.6.0 (including)7.6.0 (including)
Typo3Typo37.6.1 (including)7.6.1 (including)
Typo3Typo37.6.2 (including)7.6.2 (including)
Typo3Typo37.6.3 (including)7.6.3 (including)
Typo3Typo37.6.4 (including)7.6.4 (including)
Typo3Typo37.6.5 (including)7.6.5 (including)
Typo3Typo37.6.6 (including)7.6.6 (including)
Typo3Typo37.6.7 (including)7.6.7 (including)
Typo3Typo37.6.8 (including)7.6.8 (including)
Typo3Typo38.1.1 (including)8.1.1 (including)
Typo3-srcUbuntuprecise*
Typo3-srcUbuntutrusty*

References