Description
TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Limit Login Attempts Security Bypass (2.6.4)
WordPress Plugin Digital River Global Commerce Supply Chain Attack [Polyfill.io] (2.0.2)
MySQL CVE-2019-2968 Vulnerability (CVE-2019-2968)
Drupal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2010-2471)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-5205)