Description
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google Authenticator-Per User Prompt Timing Attack (0.6)
TCExam Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-5743)
WordPress Plugin Simple Job Board Cross-Site Scripting (2.4.3)
Dolibarr Incorrect Authorization Vulnerability (CVE-2020-12669)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3176)