CVE-2024-47780 is a medium-severity vulnerability affecting TYPO3, an open-source Content Management Framework. Backend users could inadvertently view restricted pages in the page tree, even without proper access, if mount points were misconfigured or if pages were set to allow "everybody" access. While users could see these pages, they could not manipulate them, limiting the direct impact to information disclosure. The vulnerability has a CVSS score of 4.3 (Medium), indicating a low attack complexity and requiring low privileges, but with a limited impact on confidentiality. There is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. Organizations are advised to update to TYPO3 versions 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, or 13.3.1 to remediate this issue, as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.4.46CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.5.40CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | ||
>= 12.0.0, < 12.4.21CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | ||
>= 13.0.0, < 13.3.1CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.