CVE-2012-3527 is a critical vulnerability affecting TYPO3 versions 4.5.x, 4.6.x, and 4.7.x, where a missing signature (HMAC) in view_help.php allows remote authenticated backend users to unserialize arbitrary objects. This could lead to the execution of arbitrary PHP code, resulting in potential compromise of confidentiality, integrity, and availability. With a CVSS score of 4.6, it requires authenticated access and high attack complexity, but the potential impact is significant. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.5.0, < 4.5.19CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | ||
>= 4.6.0, < 4.6.12CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | ||
>= 4.7.0, < 4.7.4CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.