CVE-2010-3714 is a critical arbitrary file disclosure vulnerability affecting TYPO3 versions 4.2.x, 4.3.x, and 4.4.x. The flaw resides in the jumpUrl (access tracking) implementation, which improperly compares hash values during access control, allowing remote attackers to read arbitrary files. With a CVSS score of 7.1 (High) and a FAUCET Risk Score of 98/100, this vulnerability is easily exploitable over the network with medium attack complexity, leading to complete confidentiality compromise. While not currently on the KEV or Hot List, exploit modules are publicly available in Metasploit and ExploitDB, indicating a high potential for exploitation. Despite its age, the EPSS score suggests it remains a relevant threat, though there is no recorded community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.0CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:4.2.0:*:*:*:*:*:*:* | ||
4.2.1CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:4.2.1:*:*:*:*:*:*:* | ||
4.2.2CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:4.2.2:*:*:*:*:*:*:* | ||
4.2.3CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:4.2.3:*:*:*:*:*:*:* | ||
4.2.4CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:4.2.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.