TYPO3 contains a flaw related to the Extension Manager that may allow a remote authenticated attacker to use a crafted parameter to access and potentially modify arbitrary files under unspecified specific circumstances. No further details have been provided.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Authentication Required
Solution
Upgrade to version 4.2.15, 4.3.7, 4.4.4 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.