TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Typo3 | Typo3 | 10.0.0 (including) | 10.4.46 (excluding) |
Typo3 | Typo3 | 11.0.0 (including) | 11.5.40 (excluding) |
Typo3 | Typo3 | 12.0.0 (including) | 12.4.21 (excluding) |
Typo3 | Typo3 | 13.0.0 (including) | 13.3.1 (excluding) |