CVE-2020-28917 is a data exposure vulnerability affecting the view_statistics extension (before version 2.0.1) for TYPO3, which inadvertently saves all GET and POST data from frontend requests to the database. This could lead to the storage of sensitive information, such as cleartext passwords if extensions like felogin are present. Rated Medium severity (CVSS 6.5), it has a low attack complexity and requires low privileges, with a high potential for confidentiality impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.1CPE matchmatch criteria | cpe:2.3:a:view_frontend_statistics_project:view_frontend_statistics:*:*:*:*:*:typo3:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.